CISA

Johnson Controls EasyIO Neo Series EC and CW Controllers

From Cybersecurity and Infrastructure Security Agency ↗

Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials andsession data.

The following versions of Johnson Controls EasyIO Neo Series EC and CW Controllers are affected:

EasyIO Neo Series EC Controllers V3.3b62 (CVE-2026-64893)

EasyIO Neo Series EC Controllers V3.3b63 (CVE-2026-64893)

EasyIO Neo Series CW Controllers V3.3b24 (CVE-2026-64893)

EasyIO Neo Series CW Controllers V3.3b25 (CVE-2026-64893)

Vendor

Equipment

Johnson Controls

Johnson Controls EasyIO Neo Series EC and CW Controllers

Cleartext Transmission of Sensitive Information

Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy

Countries/Areas Deployed: Worldwide

Company Headquarters Location: Ireland

Johnson Controls is aware of a vulnerabi...