The Password Is Baked Into the Building: Hard-Coded Keys Found in Controllers Running Offices, Factories, and Energy Sites
The building you work in is run by small computers you've never seen — and a new federal advisory says one widely deployed line of them ships with a password permanently baked into its software. CISA warns that flaws in Johnson Controls' EasyIO FG building controllers could let an attacker gain full unauthorized access to the device itself, no sophisticated hacking required.
Bottom Line
This isn't a story about one vendor's bad week — it's a reminder that the physical world now runs on small, forgettable computers, and some of them ship with the keys already inside. The CISA advisory gives defenders a head start, but hard-coded credentials have a long, ugly track record of being weaponized at scale once they become public knowledge. The race between patching and exploitation starts now.