CVE-2025-61738 Details
Description
Under certain circumstances, attacker can capture the network key, read or write encrypted packets on the PowerG network.
A vulnerability exists in Johnson Controls PowerG, IQPanel and IQHub products, allowing attackers to capture the network key and read or write encrypted packets on the PowerG network. This issue could also facilitate a replay attack. The vulnerability affects multiple versions of PowerG, IQPanel 2, IQPanel 2+, and IQPanel 4.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 22, 2025CISA-ADP
Assessed Dec 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-350-02 | [email protected] | AdvisoryBundleRemedy |
| https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories | [email protected] | AdvisoryBundleVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-319 | Cleartext Transmission of Sensitive Information | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Johnson Controls PowerG | All versions |
CPE
Remediation
| |
| Johnson Controls IQHub | All versions |
CPE
Remediation
| |
| Johnson Controls IQPanel 2 | All versions |
CPE
Remediation
| |
| Johnson Controls IQPanel 2+ | All versions |
CPE
Remediation
| |
| Johnson Controls IQPanel 4 | >= 2, < 2.1.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 22, 2025 | New CVE Received | [email protected] |
Volerion