CVE-2026-71453: Medium severity Johnson Controls EasyIO FS32 vulnerability
Published Oct 1, 2026
·Updated
- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack.
This issue affects EasyIO FS32: before 3.0b63.
Affected Software
1 affected component
Johnson Controls EasyIO FS32<3.0b63
Event History
Oct 1, 2026
CVE Published
via MITRE·09:10 PM
Data Sourced
via MITRE·09:10 PM
DescriptionWeakness
Data Sourced
via NVD·10:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which versions should be prioritized for remediation?
Johnson Controls EasyIO FS32 versions before 3.0b63 are affected. Upgrade to version 3.0b63 or later if available through the vendor.
2
What kind of weakness is involved?
The issue is an external control of file name or path vulnerability that allows a traversal attack. The provided information does not specify the required access level, attack vector, or impact beyond traversal.