CVE-2026-71448
Received Received - Intake

Insecure Default Initialization Leading to Authentication Abuse in Johnson Controls EasyIO FS32

Vulnerability report for CVE-2026-71448, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Johnson Controls

Description

: Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse. This issue affects EasyIO FS32: before 3.0b63.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
johnson_controls easyio_fs32 to 3.0b63 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1188 The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Default Initialization of Resource issue in Johnson Controls EasyIO FS32 devices. It allows authentication abuse due to improper default settings, potentially letting unauthorized users gain access without proper credentials.

Detection Guidance

Detection of this vulnerability requires checking the version of Johnson Controls EasyIO FS32 installed on your system. If the version is before 3.0b63, the system is vulnerable. No specific commands are provided in the available context to detect this vulnerability.

Impact Analysis

An attacker could exploit this to bypass authentication, gain unauthorized access to the system, and manipulate device operations. This may lead to data breaches, system disruptions, or unauthorized control of connected environments.

Compliance Impact

This vulnerability could lead to unauthorized access, violating data protection requirements under GDPR and HIPAA. It may result in non-compliance due to potential data breaches or unauthorized exposure of sensitive information.

Mitigation Strategies

Update Johnson Controls EasyIO FS32 to version 3.0b63 or later to address the insecure default initialization issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71448. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart