Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials andsession data.
The following versions of Johnson Controls EasyIO Neo Series EC and CW Controllers are affected:
EasyIO Neo Series EC Controllers V3.3b62 (CVE-2026-64893)
EasyIO Neo Series EC Controllers V3.3b63 (CVE-2026-64893)
EasyIO Neo Series CW Controllers V3.3b24 (CVE-2026-64893)
EasyIO Neo Series CW Controllers V3.3b25 (CVE-2026-64893)
Vendor
Equipment
Johnson Controls
Johnson Controls EasyIO Neo Series EC and CW Controllers
Cleartext Transmission of Sensitive Information
Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy