Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system.
The following versions of Johnson Controls EasyIO Neo Series EC and CW Controllers are affected:
EasyIO Neo Series EC Controllers V3.3b63 (CVE-2026-64892)
EasyIO Neo Series EC Controllers V3.3b62 (CVE-2026-64892)
EasyIO Neo Series CW Controllers V3.3b25 (CVE-2026-64892)
EasyIO Neo Series CW Controllers V3.3b24 (CVE-2026-64892)
Vendor
Equipment
Johnson Controls
Johnson Controls EasyIO Neo Series EC and CW Controllers
Exposure of Sensitive Information to an Unauthorized Actor
Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy