MAJOR

Security Flaws in Meari and Johnson Controls Exposed

Vulnerabilities in Meari IoT and Johnson Controls devices could lead attackers to access sensitive information and manipulate systems.

By TradepilotUSA News Desk

Published · 2 min read

Johnson Controls Vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a significant vulnerability in Johnson Controls' EasyIO Neo Series EC and CW Controllers. The affected versions include EC Controllers V3. 3b63, V3.

3b62, and CW Controllers V3. 3b25, V3. 3b24.

This vulnerability, identified as CVE-2026-64892, could allow attackers to gain unauthorized access to sensitive information, potentially leading to further attacks on building automation systems.

The EasyIO Neo Series controllers are used in building automation to manage HVAC, lighting, and energy systems. Johnson Controls, headquartered in Ireland, has acknowledged the vulnerability and released fixed versions, specifically EC firmware V3. 3b64 and CW firmware V3.

3b26. CISA recommends that users upgrade to these fixed versions to mitigate the risk of exploitation.

CISA has not reported any known public exploitation of this vulnerability. However, they advise users to implement defensive measures, such as monitoring network traffic and applying the principle of least privilege to all accounts interacting with the affected devices.

Meari IoT Cloud Platform Vulnerabilities

In a separate advisory, CISA has highlighted critical vulnerabilities in the Meari IoT Cloud Platform OpenAPI Service. These vulnerabilities, identified as CVE-2026-101104 and CVE-2026-96613, could allow attackers to manipulate device configurations and access sensitive information, including device credentials and network data, without proper authorization.

The vulnerabilities affect all versions of the Meari IoT Cloud Platform OpenAPI Service. Despite CISA's attempts to coordinate with Meari, the company has not responded, and no fix is planned for these vulnerabilities. CISA advises users to contact Meari for support and to implement recommended cybersecurity strategies to protect their systems.

CISA emphasizes the importance of minimizing network exposure for control system devices, using secure methods like VPNs for remote access, and isolating control system networks from business networks. No known public exploitation of these vulnerabilities has been reported.

Recommendations and Next Steps

CISA recommends that organizations take proactive measures to defend against these vulnerabilities. For Johnson Controls' devices, users should upgrade to the latest firmware versions and follow the company's hardening guidelines. For Meari IoT devices, users should implement network security measures and contact the vendor for further assistance.

Both advisories stress the importance of performing proper impact analysis and risk assessment before deploying defensive measures. CISA continues to provide resources and guidance on their website for improving industrial control systems cybersecurity.

Sources (1)

TradepilotUSA News writes each story in its own words from the independent reports listed above and links to them. How we report · Report a correction

More stories

More Tech