CVE-2026-21659

CRITICAL

Frick Controls Quantum HD <=10.22 - RCE

Title source: llm
STIX 2.1

Description

Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in Johnson Controls Frick Controls Quantum HD allow an unauthenticated attacker to execute arbitrary code on the affected device, leading to full system compromise. This issue affects Frick Controls Quantum HD: Frick Controls Quantum HD version 10.22 and prior.

Scores

CVSS v3 9.8
EPSS 0.0031
EPSS Percentile 54.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-22 CWE-23
Status published
Products (1)
johnsoncontrols/frick_controls_quantum_hd_firmware < 10.22
Published Feb 27, 2026
Tracked Since Feb 27, 2026