vulnerability Johnson Controls Inc. TL280 A critical vulnerability (CWE-327) exists in Johnson Controls Inc.'s TL280 firmware, allowing attackers to access sensitive information on the device. The vulnerability stems from hardcoded credentials embedded directly in the firmware. Affected versions include TL280 < 5.63, and the device is deployed worldwide. Johns… CISA Advisories · Aug 6, 2026 Critical CVE-2026-27871cwe-327firmwareics