ICSA-26-218-02
·
Published 2026-08-06
·
View on CISA ICS-CERT ↗
Johnson Controls Inc. TL280
CVSS 4.1
MEDIUM
Risk Summary
Successful exploitation of this vulnerability could allow an attacker to access sensitive information on the device.
CVEs (1)
Remediations
- To help reduce the risk of exploitation, Johnson Control suggests considering the following defensive measures: Apply firmware update 5.63.
- Johnson Controls suggests the following defensive measures: Restrict network access to affected cameras to trusted management VLANs only - do not expose these devices directly to the internet or untrusted network segments.
- Monitor device access logs for any anomalous authentication activity.
- Rotate any shared or downstream credentials that may have been derived from or associated with the hard-coded values.
- Implement network segmentation and place ICS/SCADA devices and systems behind firewalls, isolating them from the business network.
- When remote access is required, use secure methods such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be kept up to date.
- Minimize network exposure for all control system devices and/or systems; ensure they are not accessible from the internet.
- Conduct regular firmware integrity checks to detect unauthorizedmodifications.
- For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-08 at the following location: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories
Affected Vendors
Johnson Controls Inc.
Affected Products (1)
Johnson Controls Inc.
·
TL280
<5.63
Affected Sectors
Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more