S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Misconfiguration·Updated Aug 30, 2026

Johnson Controls Frick Quantum HD Default Login Scanner

This scanner detects the use of Johnson Controls Frick Quantum HD in digital assets.

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
Detail

The Johnson Controls Frick Quantum HD Compressors are widely used in industrial refrigeration applications, particularly in cold storage and food processing facilities. These systems are designed to provide precise control and monitoring of refrigeration compressors. By utilizing advanced algorithms, they ensure optimal performance and energy efficiency. They are crucial in maintaining temperature stability in environments where controlled refrigeration is essential. These compressors are manufactured by Johnson Controls, a leading company in building products and technology solutions, renowned for its HVAC systems.

The scanner focuses on detecting the default login vulnerability associated with Johnson Controls Frick Quantum HD Compressors. This vulnerability arises when these compressors are left with factory-default PINs that grant access to their control panels. Such configurations can permit unauthorized individuals to gain full control over the compressor systems. Detecting this vulnerability is crucial since default credentials are a common oversight that can lead to substantial security risks. The focus is on identifying systems that haven't been adequately secured against unauthorized access.

The detection process involves sending crafted HTTP POST requests to the system's login endpoint using a set of default PIN codes. The request payload includes various default PINs such as 1, 2, 3, etc. Successful authentication is determined by analyzing the HTTP response for indicators such as a status code of 200 and specific headers identifying an authorized session. This method efficiently pinpoints installations at risk due to default login settings, leveraging specific knowledge about the HTTP headers involved.

Exploitation of this vulnerability can lead to serious consequences, such as unauthorized control and manipulation of compressor settings, potentially causing malfunctions. In industrial setups, this can disrupt operations, spoil temperature-sensitive goods, or lead to unsafe working conditions. It may also allow attackers to use the system as an entry point for further intrusion into the organization's network.

REFERENCES

Solution Advice
  • Change default PINs immediately after installation to secure the compressor control panels.
  • Implement strong PIN policies that enforce complexity and periodic updates.
  • Regularly review and audit access logs to detect unauthorized login attempts.
  • Enable additional security measures, such as two-factor authentication, where possible.
  • Conduct regular security assessments to ensure compliance with best practices and identify potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.