Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

Frick Controls Quantum HD: Unvalidated Input Allows Unauthorized Actions

CVE-2026-21656
Summary

The Frick Controls Quantum HD version 10.22 and earlier fails to properly check user input, allowing a potential attacker to execute unauthorized actions before the device's security checks. This could compromise the security of the device. Update to the latest version of Frick Controls Quantum HD to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
johnsoncontrols frick_controls_quantum_hd_firmware <= 10.22
Original title
Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters m...
Original description
Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.
nvd CVSS3.1 9.8
nvd CVSS4.0 8.8
Vulnerability type
CWE-94 Code Injection
Published: 27 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026