Cyber Resilience
← All news

Johnson Controls Inc. TL280

Our takeCISA published ICSA-26-218-02: Johnson Controls TL280 <5.63 uses broken cryptography that can expose sensitive device data. Update to 5.63 or later.
Sources (1)
What this means for you — Security leader:Update TL280 devices to firmware 5.63 or later; the broken cryptography (CVSS 4.1) can expose sensitive device data.
What this means for you — Lean IT orgs:If you have a Johnson Controls TL280 security panel or communicator, update its firmware to 5.63 or later to protect the information it stores.
What this means for you — MSP:Check client environments for any Johnson Controls TL280 units running below 5.63 and schedule firmware updates; this is a low-severity crypto issue but still requires patching.
What this means for you — Researcher:Review the full ICSA-26-218-02 advisory and associated CSAF for implementation details on the broken cryptography in TL280 <5.63.