Junglewise Threat Intelligence

CVE-2026-64893: Johnson Controls EasyIO Neo Series EC and CW Controllers cleartext transmission

CVE-2026-64893 · Severity: high · Published 2026-10-01

Vendors: Johnson Controls.

Executive brief

Johnson Controls EasyIO Neo Series EC and CW Controllers are automation devices used to manage building systems and critical infrastructure operations. The controllers transmit sensitive information including credentials and session data in cleartext over the network, allowing attackers to intercept and read this data if they gain network access. This exposure could lead to unauthorized control of building systems, data theft, or further compromise of operational technology environments.

Technical details

The controllers transmit sensitive information including credentials and session data without encryption, enabling network eavesdropping attacks. An attacker positioned on the network (adjacent or local network access) can passively intercept these transmissions and extract credentials or session tokens. The vulnerability affects multiple firmware versions across both EC and CW controller variants, and patched versions have been released by the vendor.

Affected products

  • Johnson Controls EasyIO Neo Series EC Controller V3.3b62, V3.3b63
  • Johnson Controls EasyIO Neo Series CW Controller V3.3b24, V3.3b25

Timeline

  • 2026-10-01: disclosed: CISA ICS Advisory ICSA-26-274-05 published