# Hardcoded Credentials Flaw Hits Johnson Controls TL280

Published: 2026-08-06 · Severity: medium · Sectors: manufacturing, government-national, transportation, energy
Canonical: https://vorant.io/reports/ce3630c7-91c8-519d-85f9-f6b609f57aef/hardcoded-credentials-flaw-hits-johnson-controls-tl280

> Johnson Controls TL280 cameras below firmware 5.63 contain hardcoded credentials that could expose sensitive device information.

CISA has published an advisory for CVE-2026-27871, a hardcoded credentials vulnerability affecting Johnson Controls TL280 camera firmware versions prior to 5.63. The flaw stems from embedded authentication values in the firmware, which are classified under CWE-327 (Use of a Broken or Risky Cryptographic Algorithm), and could allow an attacker with access to the credentials to reach sensitive information on the device.

The vulnerability has high attack complexity and no known public exploitation has been reported. Johnson Controls, headquartered in Ireland, deploys TL280 devices worldwide across critical infrastructure sectors including Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, and Energy. The vendor recommends applying firmware update 5.63, restricting network access to trusted management VLANs, segmenting ICS/SCADA networks from business networks, monitoring for anomalous authentication activity, rotating any derived credentials, and using VPNs for necessary remote access. The vulnerability was reported to CISA by a researcher at VulnCheck.

## Mentioned in this report

- Vulnerabilities: CVE-2026-27871

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-218-02

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ce3630c7-91c8-519d-85f9-f6b609f57aef/hardcoded-credentials-flaw-hits-johnson-controls-tl280.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
