CVE-2026-21660: Johnsoncontrols Frick Controls Quantum Hd Firmware

Critical severity, CVSS 9.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, and potential misuse or system compromise This issue affects Frick Controls Quantum HD version 10.22 and prior.

Affected products

  • Johnsoncontrols Frick Controls Quantum Hd Firmware: up to and including 10.22

Published 2026-02-27. Last modified 2026-08-24.