{"id":"CVE-2026-21660","title":"A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, an…","summary":"A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, an…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-256","CWE-522"],"vendor":"johnsoncontrols","product":"frick_controls_quantum_hd_firmware","affected":["frick_controls_quantum_hd_firmware <= 10.22"],"published":"2026-02-27","updated":"2026-08-24","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-21660","references":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-057-01","label":"productsecurity@jci.com"},{"url":"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories","label":"productsecurity@jci.com"}],"tags":["nvd"],"epss":0.0023,"epssPercentile":0.1403,"ingestedAt":"2026-08-24T19:10:00.458Z","slug":"CVE-2026-21660","body":"## Overview\n\nA Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, and potential misuse or system compromise\n\n\nThis issue affects Frick Controls Quantum HD version 10.22 and prior.\n\n## Affected\n\n- `frick_controls_quantum_hd_firmware <= 10.22`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}