CVE-2026-21660

Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, and potential misuse or system compromise This issue affects Frick Controls Quantum HD version 10.22 and prior.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:johnsoncontrols:frick_controls_quantum_hd_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:frick_controls_quantum_hd:-:*:*:*:*:*:*:*

History

02 Mar 2026, 18:23

Type Values Removed Values Added
First Time Johnsoncontrols frick Controls Quantum Hd
Johnsoncontrols frick Controls Quantum Hd Firmware
Johnsoncontrols
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://www.cisa.gov/news-events/ics-advisories/icsa-26-057-01 - () https://www.cisa.gov/news-events/ics-advisories/icsa-26-057-01 - Third Party Advisory, US Government Resource
References () https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories - () https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories - Vendor Advisory
CWE CWE-522
CPE cpe:2.3:h:johnsoncontrols:frick_controls_quantum_hd:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:frick_controls_quantum_hd_firmware:*:*:*:*:*:*:*:*

27 Feb 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-27 10:16

Updated : 2026-03-02 18:23


NVD link : CVE-2026-21660

Mitre link : CVE-2026-21660

CVE.ORG link : CVE-2026-21660


JSON object : View

Products Affected

johnsoncontrols

  • frick_controls_quantum_hd
  • frick_controls_quantum_hd_firmware
CWE
CWE-256

Plaintext Storage of a Password

CWE-522

Insufficiently Protected Credentials