As reported by CISA in advisory ICSA-26-279-01, Johnson Controls EasyIO FG series building automation controllers contain two high-severity vulnerabilities — CVE-2026-27872 and CVE-2026-27873 — both scoring CVSS v3.1 7.7. The flaws stem from hard-coded credentials and improper privilege management, enabling full unauthorized device compromise. What elevates this advisory beyond a routine patch notification is that no fix will ever arrive: Johnson Controls has confirmed the EasyIO FG Series reached End-of-Life and End-of-Support status, having not been manufactured or sold since before 2019. The source code is no longer available.
| Field | Detail |
|---|---|
| CVEs | CVE-2026-27872, CVE-2026-27873 |
| CVSS v3.1 | 7.7 (High) |
| Affected Product | Johnson Controls EasyIO FG firmware ≤2.0b52 |
| Vulnerability Type | Hard-coded Credentials; Improper Privilege Management |
| Impact | Full unauthorized device access |
| Patch Available | No — Product is EOL/EOS; source code unavailable |
| Active Exploitation | Not confirmed; risk is elevated given unpatchable nature |
Why This Matters
This advisory crystallizes one of the most persistent and structurally difficult problems in operational technology security: orphaned devices running indefinitely in critical environments with no vendor remediation path. EasyIO FG controllers are building automation system (BAS) devices deployed across Critical Manufacturing, Commercial Facilities, Government Services, Transportation Systems, and Energy sectors — worldwide. These are not inconsequential edge devices; they manage HVAC, access control, and environmental systems whose compromise can cascade into physical safety and operational continuity impacts.
The root cause — hard-coded credentials — is among the most preventable classes of vulnerability in embedded systems engineering. That such a flaw persists in devices that were commercially sold and deployed for years underscores the immaturity of secure SDLC practices in the OT/BAS vendor ecosystem. The fact that Johnson Controls cannot issue a patch because the source code is gone should be a wake-up call for every organization that has not catalogued its OT asset inventory against vendor lifecycle statuses.
When a vendor loses the ability to patch a device still operating in your environment, your risk register is no longer about vulnerability management — it is about architecture and lifecycle management.
Who Is at Risk
Shield53 Recommendations
Immediate Actions
- Conduct emergency asset discovery — Scan all BAS/OT network ranges for EasyIO FG devices. These are likely unmanaged or forgotten. Shodan and Censys queries for default service banners can identify externally exposed units.
- Eliminate all Internet exposure — If any EasyIO FG device is reachable from the Internet, remove it immediately. There is no configuration change that makes these devices safe for public Internet exposure.
- Enforce strict network segmentation — Place all EasyIO FG devices on isolated VLANs with no routable path to enterprise IT or the Internet. Allow only required protocol traffic from explicitly whitelisted engineering workstations.
- Disable insecure services — Disable Telnet and any unnecessary exposed ports or services on these devices where the device interface permits.
- Deploy compensating monitoring — Enable logging where supported and forward to a SIEM. Monitor for repeated failed login attempts, unusual source IPs, and any root-level or administrative access events. Deploy network IDS rules for the EasyIO FG management protocols.
Strategic Actions
- Accelerate migration planning — Johnson Controls recommends migrating to the EasyIO Neo R1 Series. Build a budgeted, prioritized replacement plan with timelines keyed to risk exposure (Internet-facing first, then critical infrastructure sites).
- Formalize OT lifecycle management — Establish a vendor EOL/EOS tracking process for all OT assets. You should know — before CISA does — which devices in your environment can no longer be patched.
- Assume hard-coded credential exposure is systemic — Any embedded device from a vendor that has gone EOL without source code retention should be assumed to carry similar latent vulnerabilities. Audit accordingly.
The harder truth is this: CISA's advisory is necessary, but the absence of a patch means the real remediation is capital expenditure and network architecture — not configuration. Security teams should ensure facility owners and operational leadership understand that the cost of inaction is not theoretical. A compromised BAS controller in a transportation hub or energy facility is a physical safety incident, not just an IT ticket.