Johnson Controls EasyIO Neo Series EC and CW Controllers
CISA discloses low-severity information exposure CVE-2026-64892 in Johnson Controls EasyIO Neo EC and CW controllers.
CISA republished Johnson Controls advisory JCI-PSA-2026-20 covering information exposure in EasyIO Neo Series EC and CW controllers. CVE-2026-64892 (CWE-200) could let an attacker obtain sensitive information useful for further attacks against the building-automation system. Affected versions are EC V3.3b62 and V3.3b63 and CW V3.3b24 and V3.3b25. CVSS v3.1 is 3.5 (low), and CISA reports no known public exploitation.