Johnson Controls Frick Controls Quantum HD Unauthenticated Remote Code Execution and Information Disclosure Vulnerability

Vulnerability

A vulnerability allowing unauthenticated remote code execution and information disclosure through local file inclusion has been identified in Johnson Controls Frick Controls Quantum HD versions 10.22 and prior. This vulnerability allows an unauthenticated attacker to execute arbitrary code on the affected device, leading to a full system compromise.

Impact

Exploitation of this vulnerability can result in pre-authentication remote code execution, unauthorized information disclosure, and a complete compromise of the affected system.

Added: Feb 27, 2026, 10:19 AM
Updated: Feb 27, 2026, 2:13 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
0.0
relevance
3.3
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.