CVE-2026-21658

CRITICAL

Johnson Controls Frick Controls Quantum HD <=10.22 - Code Injection

Title source: llm
STIX 2.1

Description

Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0063
EPSS Percentile 45.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
johnsoncontrols/frick_controls_quantum_hd_firmware < 10.22
Published Feb 27, 2026
Tracked Since Feb 27, 2026