CVE-2026-21656: Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Execution
Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21656?
CVE-2026-21656 has been classified as a high severity vulnerability due to its potential for unauthenticated remote code execution.
How do I fix CVE-2026-21656?
To mitigate CVE-2026-21656, users should apply the latest patches provided by Johnson Controls for Frick Controls Quantum HD.
What are the risks associated with CVE-2026-21656?
The risks associated with CVE-2026-21656 include unauthorized remote access and control over devices that could lead to further exploitation or disruption.
What products are affected by CVE-2026-21656?
CVE-2026-21656 affects Johnson Controls Frick Controls Quantum HD versions up to 10.22.
Is authentication required to exploit CVE-2026-21656?
No, CVE-2026-21656 can be exploited without authentication, making it particularly dangerous.