Johnson Controls Inc. TL280
MonitorCVSS 4.1ICS-CERT ICSA-26-218-02Aug 6, 2026
Johnson Controls
Attack path
Attack VectorNetwork
Auth RequiredHigh
ComplexityHigh
User InteractionNone needed
Summary
The Johnson Controls TL280 security camera controller contains a weak cryptographic vulnerability (CWE-327) that allows an attacker with high-privilege network access to extract sensitive information from the device. Affected versions are below 5.63. Successful exploitation could lead to disclosure of credentials or other sensitive data that could enable unauthorized access to facility systems or surveillance capabilities.
What this means
What could happen
An attacker with high-privilege access to the network could extract sensitive information from the device, potentially including credentials or other data used to manage security cameras and related systems. This could enable lateral movement within the facility or unauthorized surveillance.
Who's at risk
This affects security camera systems in facilities that use Johnson Controls TL280 devices, including water authorities, electric utilities, and other critical infrastructure operators that rely on IP-based surveillance for facility monitoring and security.
How it could be exploited
An attacker must first gain network access to the TL280 and possess high-privilege management credentials. Once authenticated, they can exploit a weak cryptographic vulnerability (CWE-327) to access sensitive data stored on the device. The attacker would need administrative or engineering access to the device's management interface.
Prerequisites
- Network access to the TL280 management interface
- High-privilege credentials (administrative or engineering account)
- Device running firmware version below 5.63
remotely exploitablehigh privilege access requiredweak cryptography (CWE-327)potential for credential exposure
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (1)
ProductAffected VersionsFix Status
TL280<5.63Fix available
Remediation & Mitigation
0/5
Do now
0/2WORKAROUNDRestrict network access to TL280 devices to management VLANs only; block direct internet access
HARDENINGMonitor device access logs for unusual authentication activity
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
HOTFIXUpdate TL280 firmware to version 5.63 or later
HARDENINGRotate any shared credentials associated with the device or used downstream from it
Long-term hardening
0/1HARDENINGImplement network segmentation to isolate TL280 and other ICS devices behind firewalls, separate from business network
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/46104d40-5f78-4a03-ab84-7beb0fa7f678Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.