CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Johnson Controls Inc. TL280

criticalCVE-2026-27871
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to access sensitive information on the device. The following versions of Johnson Controls Inc. TL280 are affected: TL280 <5.63 CVSS Vendor Equipment Vulnerabilities v3 4.1 Johnson Controls Inc. Johnson Controls Inc. TL280 Use of a Broken or Risky Cryptographic Algorithm Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-27871 Hardcoded credentials refer to usernames, passwords, or other authentication information that are embedded directly into the source code of a firmware file. These credentials are often used to access system login and other areas of an application. View CVE Details Affected Products Johnson Controls Inc. TL280 Vendor: Johnson Controls Inc. Product Version: Johnson Controls Inc. TL280: <5.63 Product Status: known_affected Remediations Vendor fix To help reduce the risk of exploitation, Johnson Control suggests considering the following defensive measures: Apply firmware update 5.63. Mitigation Johnson Controls suggests the following defensive measures: Restrict network access to affected cameras to trusted management VLANs only - do not expose these devices directly to the internet or untrusted network segments. Mitigation Monitor device access logs for any anomalous authentication activity. Mitigation Rotate any shared or downstream credentials that may have been derived from or associated with the hard-coded values. Mitigation Implement network segmentation and place ICS/SCADA devices and systems behind firewalls, isolating them from the business network. Mitigation When remote access is required, use secure methods such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be kept up to date. Mitigatio

CSIRTS triage

What
Hardcoded credentials embedded in firmware allow unauthenticated access to the device.
Who is affected
TL280 devices running versions below 5.63 deployed in critical manufacturing, energy, transportation, and government facilities worldwide.
Urgency
Critical urgency; hardcoded credentials provide direct authentication bypass and unauthorized access to sensitive systems.
Action
Upgrade TL280 firmware to version 5.63 or later immediately.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch TL280

Get an email when a new TL280 advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-218-02

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-27871coverage & exploitation statusNVD · CVE.org

More from CISA Cybersecurity Advisories