CVE-2026-21658 PUBLISHED

Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Execution

Assigner: jci
Reserved: 02.01.2026 Published: 27.02.2026 Updated: 27.02.2026

Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.8

Product Status

Vendor Johnson Controls
Product Frick Controls Quantum HD
Versions Default: unaffected
  • Version Frick Controls Quantum HD version 10.22 and prior is affected

Solutions

a. Quantum HD version 10.22 through Version 11 is a previous product platform and is End Of support platform and should be upgraded to new platform with Quantum HD Unity version 12 and above. The update procedure can be found here: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories

Credits

  • Noam Moshe of Claroty Team 82 Research group finder

References

Problem Types

  • CWE-94 Improper Control of Generation of Code ('Code Injection') CWE

Impacts

  • CAPEC-242 Code Injection