---
id: CVE-2026-21660
title: "A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior\_lead to unauthorized access, exposure of sensitive information, an…"
summary: "A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior\_lead to unauthorized access, exposure of sensitive information, an…"
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-256
  - CWE-522
vendor: johnsoncontrols
product: frick_controls_quantum_hd_firmware
affected:
  - frick_controls_quantum_hd_firmware <= 10.22
published: '2026-02-27'
updated: '2026-08-24'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-21660'
references:
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-057-01'
    label: productsecurity@jci.com
  - url: >-
      https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories
    label: productsecurity@jci.com
tags:
  - nvd
epss: 0.0023
epssPercentile: 0.14051
ingestedAt: '2026-08-24T19:10:00.458Z'
---

## Overview

A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, and potential misuse or system compromise


This issue affects Frick Controls Quantum HD version 10.22 and prior.

## Affected

- `frick_controls_quantum_hd_firmware <= 10.22`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
