Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

Frick Controls Quantum HD: Unauthenticated Code Injection Risk

CVE-2026-21658
Summary

An unauthenticated attacker can inject malicious code into Frick Controls Quantum HD version 10.22 and earlier, potentially allowing them to take control of the device before a user logs in. This could compromise the device's security and sensitive data. Update to the latest version of Frick Controls Quantum HD to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
johnsoncontrols frick_controls_quantum_hd_firmware <= 10.22 –
Original title
Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient v...
Original description
Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.
nvd CVSS3.1 9.8
nvd CVSS4.0 8.8
Vulnerability type
CWE-94 Code Injection
Published: 27 Feb 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026