CVE-2015-3974: Easyio Easyio-30p-Sf

High severity, CVSS 9.0. EPSS: 1.9% chance of exploitation in the next 30 days.

EasyIO EasyIO-30P-SF controllers with firmware before 0.5.21 and 2.x before 2.0.5.21, as used in Accutrol, Bar-Tech Automation, Infocon/EasyIO, Honeywell Automation India, Johnson Controls, SyxthSENSE, Transformative Wave Technologies, Tridium Asia Pacific, and Tridium Europe products, have a hardcoded password, which makes it easier for remote attackers to obtain access via unspecified vectors.

Affected products

  • Easyio Easyio-30p-Sf
  • Easyio Easyio-30p-Sf Firmware: up to and including 0.5.20; up to and including 2.0.5.20

Published 2015-09-28. Last modified 2026-06-17.