Security & Threat Intelligence · 06.08.2026, 16:24 UTC
Johnson Controls Inc. TL280
| Schweregrad | info |
|---|---|
| CVE | ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA Advisories ↗ |
| Veröffentlicht | 06.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-27871. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to access sensitive information on the device. The following versions of Johnson Controls Inc. TL280 are affected:
TL280 <5.63
CVSS Vendor Equipment Vulnerabilities
v3 4.1 Johnson Controls Inc. Johnson Controls Inc. TL280 Use of a Broken or Risky Cryptographic Algorithm
Background
Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland
Vulnerabilities
Expand All +
CVE-2026-27871
Hardcoded credentials refer to usernames, passwords, or other authentication information that are embedded directly into the source code of a firmware file. These credentials are often used to access system login and other areas of an application. View CVE Details
Affected Products Johnson Controls Inc. TL280
Vendor:Johnson Controls Inc. Product Version:Johnson Controls Inc. TL280: <5.63 Product Status:known_affected
Remediations Vendor fixTo help reduce the risk of exploitation, Johnson Control suggests considering the following defensive measures: Apply firmware update 5.63. MitigationJohnson Controls suggests the following defensive measures: Restrict network access to affected cameras to trusted management VLANs only - do not expose these devices directly to the internet or untrusted network segments. MitigationMonitor device access logs for any anomalous authentication activity. MitigationRotate any shared or downstream credentials …