Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

Frick Controls Quantum HD: Unsecured Input Allows Unauthorized Actions

CVE-2026-21654
Summary

An outdated version of Frick Controls Quantum HD (version 10.22 or earlier) may allow unauthorized actions on the device before a user is fully authenticated. This is because the software does not properly check some user input. To protect your device, update to the latest version of Frick Controls Quantum HD.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
johnsoncontrols frick_controls_quantum_hd_firmware <= 10.22
Original title
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows OS Command Injection. Insufficient vali...
Original description
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows OS Command Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.
nvd CVSS3.1 9.8
nvd CVSS4.0 8.8
Vulnerability type
CWE-78 OS Command Injection
Published: 27 Feb 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026