Security1 publisher2 min readPublished
Johnson Controls EasyIO Neo controllers send building-system logins over plain HTTP
Johnson Controls EasyIO Neo EC and CW controllers on four V3.3 builds transmit credentials and session data in cleartext, tracked as CVE-2026-64893. Anyone who can see the management traffic can lift a login to a building's HVAC, lighting and energy controls.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The affected firmware is EC controllers V3.3b62 and V3.3b63 and CW controllers V3.3b24 and V3.3b25.
- Johnson Controls fixed the flaw in EC firmware V3.3b64 and CW firmware V3.3b26, where HTTP is disabled by default.
- For sites that cannot update yet, the vendor recommends enforcing HTTPS/TLS, disabling HTTP, firewall segmentation and ACLs on the management interface.
- CISA lists the controllers as deployed worldwide in critical manufacturing, commercial facilities, government facilities, transportation and energy.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure A captured session gives an attacker the same web console operators use for HVAC, lighting and energy, so interception can end in changed building settings.
- constraint Exploitation depends on network position, so segmentation and encrypted remote access limit who can read the traffic before any firmware change lands.
- decision Johnson Controls says its workarounds may not fully remediate the flaw, so HTTPS enforcement is a holding measure and sites still need a firmware change through OT change control.
Exploiting CVE-2026-64893 takes a view of the traffic. The flaw is CWE-319, cleartext transmission of sensitive information [6]. The advisory's detection guidance shows where the attacker sits. It tells defenders to look for ARP spoofing and other man-in-the-middle indicators on the local network segment [8]. It also points to cleartext credentials or session tokens in HTTP requests to the management interface on port 80 [8]. Both indicators put the attacker on the controller's segment or in the path between an operator's browser and the device [8]. Remote management is the other path in, and Johnson Controls wants it run over a VPN [7].
The credentials are the target. EasyIO Neo is a programmable edge controller that runs HVAC, lighting and energy systems in commercial buildings through a web interface [4]. With a password or a live session token, an attacker can use that interface the same way the operator does [1][4]. The advisory lists unauthorized configuration changes as one sign that credentials have been intercepted [8].
In each product line, the fixed build is the next build number after the last affected one [1]. Johnson Controls tells users to upgrade as soon as operationally feasible. Before that, they should review operational impact, back up configurations and test outside production where they can [10]. The vendor puts a limit on its own interim measures. "These mitigations reduce risk but may not fully remediate the vulnerability," the advisory says [12].
Firmware with HTTP off by default protects sessions from the upgrade onward [3]. In my view, any password used over HTTP on the affected builds should be treated as already read and changed once the new firmware is in. The exposure the advisory describes is the credential itself [1]. Detailed steps are in the Johnson Controls advisory JCI-PSA-2026-30 [9]. The CISA advisory covers one flaw under one identifier across all four builds and does not report exploitation in the wild [11].
What to watch
- Any revision to ICSA-26-274-05 or JCI-PSA-2026-30 that adds exploitation reports, further CVEs, or more EasyIO Neo builds to the affected list.
- Whether Johnson Controls documents credential rotation as part of the V3.3b64 and V3.3b26 upgrades.