216.73.216.233

CVE-2026-21658

· Published 27/02/2026 09:16 · Modified 27/02/2026 14:06

Labels: CVE-2026-21658 2026-02-27CVE-2026-21658CWE-94[email protected]

Essential information

Published
27/02/2026 09:16
Modified
27/02/2026 14:06
Author
Creator
CVSS
8.8 HIGH (v3) 8.8 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
johnson controls / frick controls quantum hd cpe:2.3:a:johnson_controls:frick_controls_quantum_hd:<10.22:*:*:*:*:*:*:*

References