Johnson Controls FX80 & FX90: Vulnerability Threat or Just a Patch Away?

View CSAF: Johnson Controls’ FX80 and FX90 devices have a critical vulnerability due to a third-party component flaw. With a CVSS v4 score of 8.4, attackers could remotely compromise configurations with low effort. Don’t panic—just update to the latest version. And remember, running unpatched software is like leaving your back door wide open.

Pro Dashboard

Hot Take:

**_Oh, Johnson Controls, you’ve done it again! Just when we thought we could control everything from our smartphones, you managed to throw a wrench—or more accurately, a vulnerable component—into the works. It’s like giving a toddler a drum set and expecting a symphony. Bravo, folks!_**

Key Points:

– Johnson Controls’ FX80 and FX90 devices are susceptible to a vulnerability due to a third-party component.
– The vulnerability, tagged as CVE-2025-43867, could allow attackers to access device configuration files.
– The CVSS v4 score for this vulnerability is 8.4, which translates roughly to “yikes” on the worry-meter.
– Patch updates are available for affected systems, but you’ll need to remember your login credentials for the software portal.
– CISA recommends keeping systems behind firewalls and using secure VPNs for remote access—because who doesn’t love playing cybersecurity hide and seek?

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?