CVE-2025-43875 Details
Description
Under certain circumstances a successful exploitation could result in access to the device.
A command injection vulnerability has been identified in Johnson Controls iSTAR Ultra, iSTAR Ultra SE, iSTAR Ultra G2, iSTAR Ultra G2 SE, and iSTAR Edge G2. This vulnerability, present in versions prior to 6.9.7.CU01 for iSTAR Ultra and iSTAR Ultra SE, and prior to 6.9.3 for iSTAR Ultra G2, iSTAR Ultra G2 SE, and iSTAR Edge G2, could be exploited under certain circumstances to gain unauthorized access to the affected device.
Users are advised to upgrade iSTAR Ultra and iSTAR Ultra SE to version 6.9.7.CU01 or greater, and iSTAR Ultra G2, iSTAR Ultra G2 SE, and iSTAR Edge G2 to version 6.9.3 or greater. For detailed mitigation instructions, refer to the Johnson Controls Product Security Advisories JCI-PSA-2025-14 and JCI-PSA-2025-15.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 24, 2025CISA-ADP
Assessed Dec 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-345-01 | [email protected] | AdvisoryBundleRemedy |
| https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories | [email protected] | AdvisoryBundleVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Johnson Controls iSTAR Ultra | < 6.9.7.CU01 |
CPE
Remediation
| |
| Johnson Controls iSTAR Ultra SE | All versions |
CPE
Remediation
| |
| Johnson Controls iSTAR Ultra G2 | < 6.9.3 (semver) |
CPE
Remediation
| |
| Johnson Controls iSTAR Ultra G2 SE | All versions |
CPE
Remediation
| |
| Johnson Controls iSTAR Edge G2 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 24, 2025 | New CVE Received | [email protected] |
Volerion