Junglewise Threat Intelligence

CVE-2026-64892: Johnson Controls EasyIO Neo Series EC and CW Controllers information disclosure

CVE-2026-64892 · Severity: high · Published 2026-10-01

Vendors: Johnson Controls.

Executive brief

Johnson Controls EasyIO Neo Series controllers are industrial devices used to manage building automation and control systems across critical infrastructure. A vulnerability in these controllers could expose sensitive information that attackers could use to conduct further attacks against the facility's operational technology networks, potentially disrupting manufacturing, energy, or transportation systems.

Technical details

The vulnerability allows exposure of sensitive information to an unauthorized actor on affected EasyIO Neo Series EC and CW Controllers. The vulnerability affects multiple firmware versions (V3.3b24, V3.3b25 for CW; V3.3b62, V3.3b63 for EC). Exploitation may require network access or specific preconditions depending on how the sensitive information is exposed.

Affected products

  • Johnson Controls EasyIO Neo Series EC Controllers V3.3b62, V3.3b63
  • Johnson Controls EasyIO Neo Series CW Controllers V3.3b24, V3.3b25

Timeline

  • 2026-10-01: disclosed
  • 2026-10-01: advisory: CISA ICS Advisory ICSA-26-274-04