CVE-2026-21660 is a critical vulnerability affecting Frick Controls Quantum HD firmware versions 10.22 and prior, where hardcoded email credentials are stored in plaintext. This flaw, categorized as CWE-256 and CWE-522, allows for unauthorized access, sensitive information exposure, and potential system compromise. With a CVSS v3.1 score of 9.8 (Critical), it can be exploited remotely with low attack complexity, requiring no user interaction. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion and media coverage, indicating awareness of its severe potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.22CPE matchmatch criteria | cpe:2.3:o:johnsoncontrols:frick_controls_quantum_hd_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.