CVE-2012-2607: Johnsoncontrols Network Controller
High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.
The Johnson Controls CK721-A controller with firmware before SSM4388_03.1.0.14_BB allows remote attackers to perform arbitrary actions via crafted packets to TCP port 41014 (aka the download port).
Affected products
- Johnsoncontrols Network Controller
- Johnsoncontrols Network Controller Firmware: up to and including 03.1.0.14; version 03.0 only
Published 2012-07-16. Last modified 2026-06-16.