As reported by CISA in advisory ICSA-26-274-05, Johnson Controls has disclosed CVE-2026-64893, a cleartext transmission vulnerability affecting EasyIO Neo Series EC and CW building automation controllers. While the CVSS v3 score of 5.4 (Medium) may seem modest, the nature of the exposure — unencrypted transmission of credentials and session data — creates real-world risk for facilities where these controllers are deployed at scale.
Why This Matters More Than the CVSS Suggests
The EasyIO Neo product line is a programmable edge controller used to manage HVAC, lighting, and energy systems in commercial buildings. These devices sit at the intersection of IT and operational technology (OT), often communicating across flat building networks where segmentation is poor or nonexistent.
A medium-severity cleartext transmission flaw in this context is not a theoretical concern. An attacker with any foothold on the building network — whether through a compromised IoT device, a rogue access point, or a VLAN traversal — can passively capture controller credentials and session tokens. From there, the attacker gains administrative access to building automation systems, enabling manipulation of environmental controls, scheduling disruption, or lateral movement into adjacent OT assets.
CISA's advisory identifies five critical infrastructure sectors as affected: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, and Energy. The global deployment footprint widens the exposure considerably.
Affected Products and Remediation Status
| Product Line | Affected Versions | Fixed Version |
|---|---|---|
| EasyIO Neo Series EC Controllers | V3.3b62, V3.3b63 | V3.3b64 |
| EasyIO Neo Series CW Controllers | V3.3b24, V3.3b25 | V3.3b26 |
Johnson Controls has confirmed that HTTP communication is disabled by default in the fixed firmware releases. No active exploitation in the wild has been reported at the time of disclosure, but the passive nature of this vulnerability means exploitation would likely go undetected without dedicated network monitoring.
Who Is Most at Risk
- Large commercial facilities with extensive EasyIO deployments across multiple floors or buildings, where network traffic traverses shared infrastructure
- Critical manufacturing and energy facilities where building automation controllers may share network segments with production OT assets
- Government buildings that rely on these controllers for environmental management and where credential exposure carries elevated data sensitivity concerns
- Organizations without OT network segmentation — if the building automation VLAN is reachable from general corporate or guest networks, the attack surface expands significantly
The absence of active exploitation reports should not delay remediation. Cleartext credential capture is a silent attack — by the time you detect it, credentials have already been compromised.
Shield53 Recommendations
Immediate Actions
Hardening Beyond the Patch
- Implement VLAN segmentation between building automation controllers and corporate IT networks. Controllers should not be reachable from user workstations or guest Wi-Fi without explicit firewall rules.
- Restrict management access to dedicated jump hosts within the OT administration zone. All controller administration should occur through a controlled, monitored path — not from arbitrary endpoints.
- Enable logging on all building automation network segments and forward events to your SIEM. Baseline expected traffic patterns so anomalous connections to controller interfaces trigger alerts.
- Adopt a lifecycle approach to OT firmware management. Building automation controllers are frequently deployed and forgotten; establish a quarterly review of firmware currency across all controller vendors, not just Johnson Controls.
The broader lesson here is one that bears repeating: cleartext protocols in embedded OT devices remain a persistent, underestimated risk. Vendors are slowly eliminating plaintext communications by default, but the installed base of vulnerable devices across critical infrastructure will take years to cycle out. Defenders should assume that any OT device not explicitly verified as using TLS is leaking credentials — and architect their networks accordingly.