CVE-2026-21654: Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Execution
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows OS Command Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21654?
CVE-2026-21654 is classified as a critical vulnerability due to its potential for unauthenticated remote code execution.
How do I fix CVE-2026-21654?
To address CVE-2026-21654, users should apply the latest security patches provided by Johnson Controls for the Frick Controls Quantum HD before version 10.22.
What type of attack is associated with CVE-2026-21654?
CVE-2026-21654 is associated with OS Command Injection attacks, allowing unauthorized commands to be executed on the affected system.
What systems are affected by CVE-2026-21654?
CVE-2026-21654 affects Johnson Controls Frick Controls Quantum HD versions up to 10.22.
Is CVE-2026-21654 exploitable remotely?
Yes, CVE-2026-21654 is exploitable remotely, enabling attackers to execute code without authentication.