Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.8
Frick Controls Quantum HD: Code Injection through Unvalidated Input
CVE-2026-21657
Summary
A software flaw in Frick Controls Quantum HD version 10.22 and earlier allows attackers to inject code that could harm the device before a user logs in. This means unauthorized access and potential damage to the system. Update to the latest version of Frick Controls Quantum HD to protect your device.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| johnsoncontrols | frick_controls_quantum_hd_firmware | <= 10.22 | – |
Original title
Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters m...
Original description
Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.
nvd CVSS3.1
9.8
nvd CVSS4.0
8.8
Vulnerability type
CWE-94
Code Injection
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-057-01 Third Party Advisory US Government Resource
- https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories Vendor Advisory
Published: 27 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026