# Johnson Controls Airwall Hit with Hard-coded Key Flaw That Exposes Every Deployment Simultaneously
## The Threat
Johnson Controls' Airwall platform — an industrial network access solution deployed across energy grids, government facilities, transportation networks, and critical manufacturing — contains a hard-coded cryptographic key shared across every installation worldwide. That single architectural failure means the moment one attacker recovers the key from any copy of the application binary, every Airwall deployment on the planet is exposed. There is no per-customer key, no per-device key — just one universal secret baked into the software itself.
This is the worst-case scenario for a cryptographic vulnerability. The key's presence in application code or compiled binaries means it can be extracted through reverse engineering, leaked via decompiled source, or simply published on a forum. Once that happens — and with OT/ICS products, it typically does — attackers can decrypt sensitive configuration data and database files across the entire installed base without needing credentials, network position, or any other precondition beyond knowing the key exists.
A second flaw compounds the problem: CVE-2026-34492 introduces an external control of file name or path vulnerability, giving attackers a path to read arbitrary files on the system. In combination, these two CVEs paint an ugly picture — decrypt the configuration layer to harvest credentials or keys, then leverage the path traversal to access protected files that should never be reachable from outside. Critical infrastructure operators running unpatched Airwall should treat this as an active risk requiring immediate action, not a scheduled maintenance item.
## Severity and Impact
| CVE | CVSS Score | Severity | Vector String | Attack Complexity | CWE |
|-----|------------|----------|---------------|-------------------|-----|
| CVE-2026-64887 | 6.8 | Medium | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N | High | CWE-321 (Use of Hard-coded Cryptographic Key) |
| CVE-2026-34492 | 6.8 | Medium | CVSS:3.1 | High | CWE-73 (External Control of File Name or Path) |
CVSS scores reflect vendor assessment. The Medium severity rating is technically defensible given the attack complexity, but understates operational risk for critical infrastructure deployments where the breadth of exposure — all installations, all customers, simultaneously — is the primary threat multiplier.
## Affected Products
Johnson Controls Inc. Airwall
Affected sectors per ICS-CERT:
Deployment scope: Worldwide
## Mitigations
Patch first. Johnson Controls has released version 4.1.0 as the remediation for both CVEs. All Airwall instances should be updated immediately.
For organizations that cannot patch immediately, Johnson Controls and ICS-CERT recommend the following interim controls:
For CVE-2026-64887 (Hard-coded Key):
For CVE-2026-34492 (Path Traversal):
Longer-term:
Full vendor advisory: [JCI-PSA-2026-25](https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories)
## References
---
## HackWire Analysis
The 6.8 CVSS score on CVE-2026-64887 is misleading in a way that matters. "Medium" implies a contained, qualified risk. What it actually describes is a single cryptographic secret that unlocks the entire global installed base — simultaneously, universally, without differentiation. The CVSS attack complexity is rated "High" because actually extracting a hard-coded key from a binary requires some skill. But that's a one-time effort by one attacker. Once extracted and published — and ICS/OT vulnerabilities have a well-documented history of ending up on Pastebin or in private exploit kits — the complexity drops to zero for every subsequent actor. The "High" complexity multiplier is a one-time friction tax, not a lasting protection.
This vulnerability class is not new, but its persistence in industrial control systems is remarkable. Hard-coded credentials and keys were flagged as a critical problem in ICS software over a decade ago. CISA has published guidance repeatedly. Yet here we are in 2026 with a vendor shipping an OT network access platform — something explicitly designed to control access to critical infrastructure — with a universal key embedded in the binary.
What makes Airwall particularly sensitive is its function. This isn't a general-purpose enterprise application; it's an industrial network access control product. The sectors listed in this advisory — energy, transportation, government facilities, critical manufacturing — are precisely the environments where network access control failure has physical-world consequences. Defenders in these environments should not wait for routine patch cycles. The combination of the hardcoded key and the path traversal flaw creates a reliable exploitation chain, and threat actors targeting OT infrastructure are both motivated and technically capable of chaining exactly this kind of pair.
If you operate Airwall at 4.0.4 or below, patch to 4.1.0 now. If patching requires a maintenance window, segment the management interfaces immediately and assume the key has already been extracted somewhere.
— HackWire Editorial
---
## Related Coverage