PT-2026-22324 · Johnson Controls · Quantum Hd

Noam Moshe

·

Published

2026-02-27

·

Updated

2026-03-04

·

CVE-2026-21658

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Johnson Controls Frick Controls Quantum HD versions prior to 10.22
Description A flaw exists in Johnson Controls Frick Controls Quantum HD that allows for the execution of code remotely without authentication. This is due to insufficient validation of input parameters, potentially enabling unexpected actions. The issue is a type of code injection.
Recommendations Update to a version newer than 10.22.

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-21658

Affected Products

Quantum Hd