CVE-2026-21660 PUBLISHED

Johnson Controls-Frick Quantum HD-Hardcoded Email Credentials Saved as Plaintext in Firmware

Assigner: jci
Reserved: 02.01.2026 Published: 27.02.2026 Updated: 27.02.2026

Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, and potential misuse or system compromise This issue affects Frick Controls Quantum HD version 10.22 and prior.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor Johnson Controls
Product Frick Controls Quantum HD
Versions Default: unaffected
  • Version Frick Controls Quantum HD version 10.22 and prior is affected

Solutions

a. Quantum HD version 10.22 through Version 11 is a previous product platform and is End Of support platform and should be upgraded to new platform with Quantum HD Unity version 12 and above. The update procedure can be found here: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories

Credits

  • Noam Moshe of Claroty Team 82 Research group finder

References

Problem Types

  • CWE-256: Plaintext Storage of a Password CWE

Impacts

  • CAPEC-37 Retrieve Embedded Sensitive Data