CISA Warns of Hardcoded Credentials in Johnson Controls TL280 Security Cameras

CISA published an Industrial Control Systems advisory on August 6, 2026 (ICSA-26-218-02) warning that Johnson Controls TL280 cameras running firmware versions prior to 5.63 contain hardcoded credentials that could allow an attacker to access sensitive information on the device.

The vulnerability, tracked as CVE-2026-27871 and rated 4.1 on the CVSS v3 scale, stems from the use of a broken or risky cryptographic algorithm tied to authentication values embedded directly in the device firmware. Because the credentials are fixed at the firmware level rather than generated per device, an attacker who recovers them from one unit could potentially reuse them across other TL280 deployments running the same vulnerable firmware version.

Johnson Controls, headquartered in Ireland, reports that TL280 units are deployed worldwide across Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, and Energy sectors — reflecting how widely IP camera platforms from major building-security vendors have been integrated into critical infrastructure environments. As of the advisory’s publication, CISA said it was not aware of public exploitation specifically targeting this vulnerability.

Recommended Mitigations

Johnson Controls’ primary recommended fix is to apply firmware update 5.63, which addresses the hardcoded credential weakness directly. CISA and the vendor also recommend layered compensating controls for cameras that cannot be updated immediately:

  • Restrict network access to affected cameras to trusted management VLANs only, and avoid exposing devices directly to the internet or untrusted network segments
  • Monitor device access logs for anomalous authentication activity
  • Rotate any shared or downstream credentials that may have been derived from or associated with the hardcoded values
  • Segment ICS/SCADA and physical-security device networks behind firewalls, isolated from general business networks
  • Use up-to-date VPNs for any required remote access rather than direct internet exposure

The advisory is a reminder that video surveillance hardware sits at the intersection of physical and cyber risk: a credential weakness in a camera is not just a data-exposure issue but a potential foothold into the broader network segment the camera is connected to, particularly in environments where security devices are deployed on flat, unsegmented networks.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *