CVE-2025-61740 Details
Description
Authentication issue that does not verify the source of a packet which could allow an attacker to create a denial-of-service condition or modify the configuration of the device.
An authentication vulnerability has been identified in Johnson Controls PowerG, IQPanel and IQHub products. This issue arises because the source of packets is not properly verified, potentially enabling an attacker to cause a denial-of-service condition or alter the device's configuration. The vulnerability affects multiple versions of PowerG, IQPanel 2, IQPanel 2+, IQPanel 4 and IQHub.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 22, 2025CISA-ADP
Assessed Dec 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/news-events/ics-advisories/icsa-25-350-02 | [email protected] | AdvisoryBundleRemedy |
| https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories | [email protected] | AdvisoryBundleVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-346 | Origin Validation Error | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Johnson Controls PowerG | All versions |
CPE
Remediation
| |
| Johnson Controls IQHub | All versions |
CPE
Remediation
| |
| Johnson Controls IQPanel 2 | All versions |
CPE
Remediation
| |
| Johnson Controls IQPanel 2+ | All versions |
CPE
Remediation
| |
| Johnson Controls IQPanel 4 | >= 2, < 2.1.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 22, 2025 | New CVE Received | [email protected] |
Volerion