The Cybersecurity and Infrastructure Security Agency (CISA) has published advisory ICSA-26-274-05 warning of a critical authentication bypass flaw (CVE-2026-40112, CVSS 9.8) in Johnson Controls EasyIO Neo building automation and energy management controllers. The defect enables unauthenticated network attackers to seize administrative control over facilities infrastructure, including commercial HVAC, cleanroom pressurization, and emergency ventilation systems.

Vulnerability Analysis: Session State Bypass (CWE-287)

EasyIO Neo controllers (EC-30, EC-50, and CW-series) operate as BACnet- and Modbus-compatible edge devices that govern heating, ventilation, and air conditioning across hospitals, pharmaceutical laboratories, and enterprise data centers. Configuration is performed through an integrated lighttpd web server providing REST endpoints.

According to CISA's findings, the session validation handler fails to reject HTTP requests containing a forged null session cookie header. When an attacker sends a crafted header containing an empty or malformed token string, the authorization middleware improperly defaults to an authenticated administrative state:

// Vulnerable session authentication logic in EasyIO Neo firmware handler
if (request_cookie != NULL) {
    if (strlen(request_cookie) == 0 || strcmp(request_cookie, "auth=0") == 0) {
        // Defect: Empty or zero-valued cookies default to root privilege context
        user_context.is_authenticated = 1;
        user_context.role = ROLE_FACILITY_ADMIN;
    }
}

Impact on Critical Infrastructure Facilities

By exploiting this flaw over TCP port 80 or 443, remote threat actors can manipulate temperature setpoints, disable safety alarms, or overwrite firmware logic with malicious binaries. In healthcare and pharmaceutical manufacturing environments, loss of atmospheric pressurization control can lead to product contamination and immediate regulatory shutdown.

Remediation and Defense-in-Depth Checklist

  • Apply Firmware Update: Immediately upgrade all EasyIO Neo devices to firmware v2.4.1 or higher.
  • Isolate Building Automation Networks: Disconnect building management controllers from public-facing internet routing and enforce strict Purdue Model Level 2 segmentation.
  • Implement Network Access Control: Restrict HTTP/HTTPS traffic to authorized engineering workstations using MAC address filtering and dedicated OT VLANs.