CVE-2026-21658: Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Execution
Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21658?
The severity of CVE-2026-21658 is critical due to its ability to allow unauthenticated remote code execution.
How do I fix CVE-2026-21658?
To fix CVE-2026-21658, update the Johnson Controls Frick Controls Quantum HD to the latest version beyond 10.22.
What systems are affected by CVE-2026-21658?
CVE-2026-21658 affects the Johnson Controls Frick Controls Quantum HD software versions up to 10.22.
Can CVE-2026-21658 be exploited remotely?
Yes, CVE-2026-21658 can be exploited remotely due to the unauthenticated nature of the vulnerability.
What type of vulnerability is CVE-2026-21658?
CVE-2026-21658 is categorized as a code injection vulnerability, allowing improper control over code generation.