CVE-2026-21656

CRITICAL

Johnson Controls Frick Controls Quantum HD <=10.22 - Code Injection

Title source: llm
STIX 2.1

Description

Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0039
EPSS Percentile 30.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
johnsoncontrols/frick_controls_quantum_hd_firmware < 10.22
Published Feb 27, 2026
Tracked Since Feb 27, 2026