Skip to content
Rota Nacional

Cyber ·

Alert: EasyIO Neo controllers vulnerable

CISA advisory on CVE-2026-64893: specific versions of Johnson Controls EasyIO Neo EC and CW controllers may transmit sensitive data in cleartext. The recommendation is to update and secure management communications.

Published on October 1, 2026, the advisory reports that CVE-2026-64893 may allow interception of sensitive information, including credentials and session data sent over the network. The alert assigns the vulnerability a CVSS 3 score of 5.4. Affected controllers are EC V3.3b62 and V3.3b63, and CW V3.3b24 and V3.3b25. EasyIO Neo is a programmable controller used in building automation, including HVAC, lighting, and energy systems.

Johnson Controls has issued fixes: firmware EC V3.3b64 and CW V3.3b26, or later versions. The advisory recommends assessing operational impact, backing up configurations, and testing updates before production deployment, in line with change procedures. If an update cannot be made immediately, it recommends enabling HTTPS/TLS, disabling HTTP, and limiting exposure through network segmentation, a firewall, and VPN for remote access. Consult the original CISA advisory and the CSAF summary to verify details and confirm current guidance.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free