CVE-2026-21657: Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Execution
Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21657?
The severity of CVE-2026-21657 is classified as critical due to the risk of unauthenticated remote code execution.
How do I fix CVE-2026-21657?
To fix CVE-2026-21657, update Johnson Controls Frick Controls Quantum HD to the latest version beyond 10.22 that addresses this vulnerability.
What type of vulnerability is CVE-2026-21657?
CVE-2026-21657 is an unauthenticated remote code execution vulnerability due to improper control of code generation.
Which versions of Johnson Controls Frick Controls Quantum HD are affected by CVE-2026-21657?
Versions of Johnson Controls Frick Controls Quantum HD up to and including 10.22 are affected by CVE-2026-21657.
What are the risks associated with CVE-2026-21657?
The risks associated with CVE-2026-21657 include unauthorized execution of arbitrary code, leading to potential system compromise or control.