Executive brief
Frick Controls Quantum HD is industrial refrigeration control equipment used globally in food storage and processing facilities. The firmware contains hardcoded email credentials stored in plaintext, allowing unauthenticated attackers with network access to extract sensitive credentials and potentially compromise the system or access connected infrastructure without authorization.
Technical details
The vulnerability is a plaintext password storage flaw (CWE-256) in which email credentials are hardcoded directly in the firmware of Frick Controls Quantum HD version 10.22 and prior. The affected component stores authentication material without encryption, making it trivially accessible to any attacker who can obtain or analyze the firmware image. No authentication is required to exploit this; network-connected devices are exploitable. A successful exploit allows attackers to extract email credentials and use them to gain unauthorized access to the device, connected systems, or external email services. Johnson Controls recommends upgrading to Quantum HD Unity version 12 or higher; versions 10.22 through 11 have reached end-of-support.
Affected products
- Johnson Controls Frick Controls Quantum HD 10.22 and prior
Timeline
- 2026-02-26: disclosed
- 2026-02-27: advisory