CVE-2026-21660

Summary

A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, and potential misuse or system compromise

This issue affects Frick Controls Quantum HD version 10.22 and prior.

Affected Software

VendorProductVersion RangeStatus
Johnson ControlsFrick Controls Quantum HDFrick Controls Quantum HD version 10.22 and prioraffected

Weaknesses

  • CWE-256: CWE-256: Plaintext Storage of a Password

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References