Junglewise Threat Intelligence

CVE-2026-64887: Johnson Controls Airwall hard-coded cryptographic key

CVE-2026-64887 · Severity: info · Published 2026-08-14

Vendors: Johnson Controls.

Executive brief

Johnson Controls Airwall is a gateway device used to secure and manage building automation and network systems. The use of a hard-coded cryptographic key in Airwall versions before 4.1 allows attackers to decrypt or forge communications, potentially compromising the confidentiality and integrity of critical building control systems.

Technical details

The vulnerability is a use of hard-coded cryptographic key issue in Johnson Controls Airwall before version 4.1. Hard-coded keys are embedded in the firmware or software, making them discoverable through reverse engineering or public disclosure. This allows an attacker with network access to the Airwall device to perform cryptanalytic attacks, potentially decrypting sensitive communications or forging authentication tokens. The specific attack vector and preconditions depend on how the key is used in the system. No patch availability information is provided in the advisory.

Affected products

  • Johnson Controls Airwall before 4.1

Timeline

  • 2026-08-14: disclosed

References

Related threats