CVE-2024-32754: Johnson Controls Kantech KT1 Door Controller, REV01

Low severity, CVSS 3.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Under certain circumstances, when the controller is in factory reset mode waiting for initial setup, it will broadcast its MAC address, serial number, and firmware version. Once configured, the controller will no longer broadcast this information.

Affected products

  • Johnson Controls Kantech KT1 Door Controller, REV01: up to and including 2.09.10
  • Johnson Controls Kantech KT2 Door Controller, REV01: up to and including 2.09.10
  • Johnson Controls Kantech KT400 Door Controller, REV01: up to and including 3.01.16

Published 2024-07-04. Last modified 2026-06-17.