As reported by CISA in advisory ICSA-26-274-05, Johnson Controls has disclosed CVE-2026-64893, a cleartext transmission vulnerability affecting EasyIO Neo Series EC and CW building automation controllers. While the CVSS v3 score of 5.4 (Medium) may seem modest, the nature of the exposure — unencrypted transmission of credentials and session data — creates real-world risk for facilities where these controllers are deployed at scale.

Security Impact: As reported by CISA in advisory ICSA-26-274-05, Johnson Controls has disclosed CVE-2026-64893, a cleartext transmission vulnerability affecting EasyIO Neo Series EC and CW building automation controllers.

Why This Matters More Than the CVSS Suggests

The EasyIO Neo product line is a programmable edge controller used to manage HVAC, lighting, and energy systems in commercial buildings. These devices sit at the intersection of IT and operational technology (OT), often communicating across flat building networks where segmentation is poor or nonexistent.

A medium-severity cleartext transmission flaw in this context is not a theoretical concern. An attacker with any foothold on the building network — whether through a compromised IoT device, a rogue access point, or a VLAN traversal — can passively capture controller credentials and session tokens. From there, the attacker gains administrative access to building automation systems, enabling manipulation of environmental controls, scheduling disruption, or lateral movement into adjacent OT assets.

CISA's advisory identifies five critical infrastructure sectors as affected: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, and Energy. The global deployment footprint widens the exposure considerably.

Affected Products and Remediation Status

Product LineAffected VersionsFixed Version
EasyIO Neo Series EC ControllersV3.3b62, V3.3b63V3.3b64
EasyIO Neo Series CW ControllersV3.3b24, V3.3b25V3.3b26

Johnson Controls has confirmed that HTTP communication is disabled by default in the fixed firmware releases. No active exploitation in the wild has been reported at the time of disclosure, but the passive nature of this vulnerability means exploitation would likely go undetected without dedicated network monitoring.

Who Is Most at Risk

  • Large commercial facilities with extensive EasyIO deployments across multiple floors or buildings, where network traffic traverses shared infrastructure
  • Critical manufacturing and energy facilities where building automation controllers may share network segments with production OT assets
  • Government buildings that rely on these controllers for environmental management and where credential exposure carries elevated data sensitivity concerns
  • Organizations without OT network segmentation — if the building automation VLAN is reachable from general corporate or guest networks, the attack surface expands significantly

The absence of active exploitation reports should not delay remediation. Cleartext credential capture is a silent attack — by the time you detect it, credentials have already been compromised.

Shield53 Recommendations

Immediate Actions

Shield53 Recommendations
Inventory your EasyIO Neo deployments. Identify all EC and CW controllers across your facility footprint and record current firmware versions. Prioritize devices on networks accessible to non-administrative users.
Upgrade firmware now. Apply EC firmware V3.3b64 or CW firmware V3.3b26 via the Johnson Controls Trust Center or your account representative. In production ICS/OT environments, validate the update on a non-critical controller first before broad rollout.
Disable HTTP if upgrade is delayed. If operational constraints prevent immediate firmware updates, verify whether HTTP can be manually disabled on affected controllers or enforce TLS through a reverse proxy or gateway in front of the controllers.
Rotate all controller credentials. Assume that any credentials transmitted over the network during the vulnerability window have been potentially exposed. Reset admin passwords and API tokens on all affected devices.
Deploy network-level monitoring. Configure IDS/IPS rules to detect plaintext HTTP traffic to and from EasyIO controller IP ranges. Any post-patch HTTP traffic may indicate misconfiguration or a rogue device.

Hardening Beyond the Patch

  • Implement VLAN segmentation between building automation controllers and corporate IT networks. Controllers should not be reachable from user workstations or guest Wi-Fi without explicit firewall rules.
  • Restrict management access to dedicated jump hosts within the OT administration zone. All controller administration should occur through a controlled, monitored path — not from arbitrary endpoints.
  • Enable logging on all building automation network segments and forward events to your SIEM. Baseline expected traffic patterns so anomalous connections to controller interfaces trigger alerts.
  • Adopt a lifecycle approach to OT firmware management. Building automation controllers are frequently deployed and forgotten; establish a quarterly review of firmware currency across all controller vendors, not just Johnson Controls.

The broader lesson here is one that bears repeating: cleartext protocols in embedded OT devices remain a persistent, underestimated risk. Vendors are slowly eliminating plaintext communications by default, but the installed base of vulnerable devices across critical infrastructure will take years to cycle out. Defenders should assume that any OT device not explicitly verified as using TLS is leaking credentials — and architect their networks accordingly.