CVE-2026-21660: medium-severity vulnerability in Johnson Controls Frick Controls Quantum HD
Johnson Controls-Frick Quantum HD-Hardcoded Email Credentials Saved as Plaintext in Firmware
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.9epss 0.2%
exploitation probability
0.2%top 87% of all CVEs
observed exploitation
nono source reports it
A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, and potential misuse or system compromise
This issue affects Frick Controls Quantum HD version 10.22 and prior.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
Johnson Controls · Frick Controls Quantum HDRelated CVEs — Johnson Controls Frick Controls Quantum HD
In the same product, most dangerous first.
CVE-2026-21654HIGHJohnson Controls -Frick Quantum HD- Unauthenticated Remote Code ExecutionEPSS 1.5%CVE-2026-21659HIGHJohnson Controls -Frick Quantum HD-Unauthenticated Remote Code Execution and Information Disclosure due to Local File InclusionEPSS 0.9%CVE-2026-21658HIGHJohnson Controls -Frick Quantum HD- Unauthenticated Remote Code ExecutionEPSS 0.6%CVE-2026-21657HIGHJohnson Controls -Frick Quantum HD- Unauthenticated Remote Code ExecutionEPSS 0.4%CVE-2026-21656HIGHJohnson Controls -Frick Quantum HD- Unauthenticated Remote Code ExecutionEPSS 0.4%