The Cybersecurity and Infrastructure Security Agency (CISA) has issued dual industrial advisories (ICSA-26-274-04 and ICSA-26-274-05) detailing information disclosure and cleartext credential transmission vulnerabilities in Johnson Controls EasyIO Neo Series EC and CW Controllers. Cataloged as CVE-2026-64892 and CVE-2026-64893, the flaws expose building management supervisory credentials, session tokens, and operational parameters across local network segments, creating severe risks for critical manufacturing plants, hospital facilities, and data centers.

Building Automation Edge Controllers in Critical Facilities

The Johnson Controls EasyIO Neo Series (comprising the EC-30, CW-20, and related variants) are 32-bit programmable edge controllers engineered for modern Building Automation and Control networks (BACnet/IP, Modbus, and Sedona Framework). They govern air handling units (AHUs), variable air volume (VAV) systems, central chiller plants, and cleanroom atmospheric pressure balances.

In enterprise data centers and pharmaceutical manufacturing facilities, precise thermal and humidity regulation is vital. Compromise of building automation controllers allows adversaries to manipulate cooling systems, trip thermal safety interlocks, and induce physical hardware failures across server racks and manufacturing lines.

Vulnerability Mechanics: Cleartext Communications (CVE-2026-64893)

Advisory ICSA-26-274-05 reveals that default management and programming communications between the EasyIO Neo controller and engineering workstations occur over unencrypted HTTP and cleartext proprietary TCP protocols (CWE-319).

An attacker located on the same local subnet or an adjacent corporate VLAN can passively sniff network packets using standard packet capture tools (e.g., Wireshark) and extract plaintext administrative credentials during operator login sequences:

POST /api/v1/auth/login HTTP/1.1
Host: 192.168.10.45:80
Content-Type: application/json

{
  "username": "hvac_admin",
  "password": "FacilityManager2026!",
  "domain": "NEO-CTRL-AHU4"
}

Furthermore, session cookies and REST API authentication tokens returned by the controller are transmitted without the Secure flag and with long expiration lifetimes, permitting session hijacking without credential brute-forcing.

Sensitive Telemetry and Configuration Leakage (CVE-2026-64892)

Complementing the transmission flaw, CVE-2026-64892 involves unauthenticated diagnostic endpoints that disclose internal controller architecture details, network routing tables, firmware build signatures, and BACnet object instance mappings to any querying client.

Advisory Alert CVE Identifier CWE Weakness Threat Vector
ICSA-26-274-04 CVE-2026-64892 CWE-200 Information Exposure Unauthenticated diagnostic query endpoints
ICSA-26-274-05 CVE-2026-64893 CWE-319 Cleartext Transmission Passive network packet capture on OT subnet

Operational Hardening Recommendations for Facility Engineers

  • Enforce HTTPS and Disable HTTP: Access the EasyIO Neo web management console and disable the plain HTTP port (port 80), forcing all traffic through TLS 1.3 encryption on port 443 with modern cipher suites.
  • Segment Building Automation Networks: Adhere strictly to the Purdue Model for industrial security. Place EasyIO controllers within an isolated Building Automation VLAN (Level 2/3 Operations) separated from corporate IT networks by a next-generation firewall.
  • Rotate BACnet and Device Passwords: Change default administrative passwords and configure individual user accounts with role-based access control rather than sharing generic operator accounts.