As reported by CISA in advisory ICSA-26-279-01, Johnson Controls EasyIO FG series building automation controllers contain two high-severity vulnerabilities — CVE-2026-27872 and CVE-2026-27873 — both scoring CVSS v3.1 7.7. The flaws stem from hard-coded credentials and improper privilege management, enabling full unauthorized device compromise. What elevates this advisory beyond a routine patch notification is that no fix will ever arrive: Johnson Controls has confirmed the EasyIO FG Series reached End-of-Life and End-of-Support status, having not been manufactured or sold since before 2019. The source code is no longer available.

Security Impact: As reported by CISA in advisory ICSA-26-279-01, Johnson Controls EasyIO FG series building automation controllers contain two high-severity vulnerabilities — CVE-2026-27872 and CVE-2026-27873 — both scoring CVSS v3.1 7.7.

FieldDetail
CVEsCVE-2026-27872, CVE-2026-27873
CVSS v3.17.7 (High)
Affected ProductJohnson Controls EasyIO FG firmware ≤2.0b52
Vulnerability TypeHard-coded Credentials; Improper Privilege Management
ImpactFull unauthorized device access
Patch AvailableNo — Product is EOL/EOS; source code unavailable
Active ExploitationNot confirmed; risk is elevated given unpatchable nature

Why This Matters

This advisory crystallizes one of the most persistent and structurally difficult problems in operational technology security: orphaned devices running indefinitely in critical environments with no vendor remediation path. EasyIO FG controllers are building automation system (BAS) devices deployed across Critical Manufacturing, Commercial Facilities, Government Services, Transportation Systems, and Energy sectors — worldwide. These are not inconsequential edge devices; they manage HVAC, access control, and environmental systems whose compromise can cascade into physical safety and operational continuity impacts.

The root cause — hard-coded credentials — is among the most preventable classes of vulnerability in embedded systems engineering. That such a flaw persists in devices that were commercially sold and deployed for years underscores the immaturity of secure SDLC practices in the OT/BAS vendor ecosystem. The fact that Johnson Controls cannot issue a patch because the source code is gone should be a wake-up call for every organization that has not catalogued its OT asset inventory against vendor lifecycle statuses.

When a vendor loses the ability to patch a device still operating in your environment, your risk register is no longer about vulnerability management — it is about architecture and lifecycle management.

Who Is at Risk

Who Is at Risk
Facilities and plant operations teams running legacy EasyIO FG controllers in any critical infrastructure environment — especially those in Energy, Transportation, and Government Facilities sectors where physical impact is most severe.
Organizations with flat BAS/OT networks where these controllers share segments with enterprise IT or have any Internet-facing exposure. Any direct Internet exposure of these devices should be treated as an active compromise risk.
Multi-site operators who may have lost track of deployed EasyIO FG units over years of facility acquisitions, mergers, or IT/OT organizational restructuring.

Shield53 Recommendations

Immediate Actions

  • Conduct emergency asset discovery — Scan all BAS/OT network ranges for EasyIO FG devices. These are likely unmanaged or forgotten. Shodan and Censys queries for default service banners can identify externally exposed units.
  • Eliminate all Internet exposure — If any EasyIO FG device is reachable from the Internet, remove it immediately. There is no configuration change that makes these devices safe for public Internet exposure.
  • Enforce strict network segmentation — Place all EasyIO FG devices on isolated VLANs with no routable path to enterprise IT or the Internet. Allow only required protocol traffic from explicitly whitelisted engineering workstations.
  • Disable insecure services — Disable Telnet and any unnecessary exposed ports or services on these devices where the device interface permits.
  • Deploy compensating monitoring — Enable logging where supported and forward to a SIEM. Monitor for repeated failed login attempts, unusual source IPs, and any root-level or administrative access events. Deploy network IDS rules for the EasyIO FG management protocols.

Strategic Actions

  • Accelerate migration planning — Johnson Controls recommends migrating to the EasyIO Neo R1 Series. Build a budgeted, prioritized replacement plan with timelines keyed to risk exposure (Internet-facing first, then critical infrastructure sites).
  • Formalize OT lifecycle management — Establish a vendor EOL/EOS tracking process for all OT assets. You should know — before CISA does — which devices in your environment can no longer be patched.
  • Assume hard-coded credential exposure is systemic — Any embedded device from a vendor that has gone EOL without source code retention should be assumed to carry similar latent vulnerabilities. Audit accordingly.

The harder truth is this: CISA's advisory is necessary, but the absence of a patch means the real remediation is capital expenditure and network architecture — not configuration. Security teams should ensure facility owners and operational leadership understand that the cost of inaction is not theoretical. A compromised BAS controller in a transportation hub or energy facility is a physical safety incident, not just an IT ticket.