Johnson Controls TL280 ships with hardcoded credentials
Firmware below 5.63 embeds authentication material directly in source, upgrade eliminates the door; the credential hygiene questions linger.
TL;DR
CISA published an advisory Wednesday for Johnson Controls TL280 devices running firmware below version 5.63, which contain hardcoded credentials enabling unauthorized access to sensitive information on affected units. Johnson Controls has issued firmware update 5.63 to eliminate the flaw. Affected sectors include critical manufacturing, energy, transportation, and government facilities. The advisory carries a CVSS v3.1 score of 4.1 (medium), low because exploitation requires high privileges and high attack complexity, though a device sitting on a flat network with default credentials changes that math quickly.
The vulnerability, tracked as CVE-2026-27871, sits in the firmware itself, credentials baked into source code, not configurable, not visible to the operator swapping out passwords through the management interface. That's the distinction that matters to the engineer Monday morning: rotating your admin password won't close this door. Only the firmware update does.
Johnson Controls's mitigation guidance is reasonable (restrict devices to trusted VLANs, monitor for anomalous authentication, segment ICS networks from the business side) but it's also the standard CISA boilerplate. The practical question is how many TL280s in the field are reachable from anything other than a properly segmented control network. The answer, as anyone who's walked a critical-manufacturing floor or a government facility's utility closet knows, is more than zero.
This is at least the sixth Johnson Controls ICS advisory CISA has published in the past twelve months, spanning iSTAR door controllers, FX Server building-automation platforms, C-CURE access-control systems, CEM AC2000, and now the TL280 alarm communicator. No single vulnerability pattern ties them together (they range from buffer overflows to certificate-validation failures to third-party component dependencies) but the cadence is worth noting for anyone managing a multi-product Johnson Controls deployment. The vendor has issued patches across each advisory, and none of these vulnerabilities has been added to CISA's Known Exploited Vulnerabilities catalog.
The CVSS scores here are modest, 4.1 under v3.1, 2.1 under v4.0, because the attack presumes high privileges and high attack complexity. But scores assume a well-architected network. A hardcoded credential on an alarm communicator that bridges physical security events to a monitoring center, sitting on a subnet that hasn't been touched since commissioning, is a different risk profile than the vector string suggests. Upgrade to 5.63.
Published ·Deep Fathom