CVE-2026-21660CRITICAL 9.8EPSS p13.0%
CVE-2026-21660CVE-2026-21660
johnsoncontrols / frick_controls_quantum_hd_firmware
Description
A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, and potential misuse or system compromise
This issue affects Frick Controls Quantum HD version 10.22 and prior.
Scoring
| CVSS 3.1 | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.23% probability of exploitation · percentile 13.0% · 2026-10-05T12:00:23Z |
| Published | 2026-02-27 |
| Last modified | 2026-08-24 |
Underlying weaknesses· 2
References
2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Plaintext Storage of a Passwordcwe-256 | 0% | live |
| Weakness | Insufficiently Protected Credentialscwe-522 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.