CVE-2025-43873: iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection - setFaultDebounce
Successful exploitation of these vulnerabilities could allow an attacker to modify firmware and gain full access to the device.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.9.3 - Upgrade
Upgrade
iSTAR Ultra G2, iSTAR Ultra G2 SE, iSTAR Edge G2to a version that resolves this vulnerability.Fixed in 6.9.3 - Upgrade
Upgrade
iSTAR Ultra, iSTAR Ultra SE, iStar Ultra LTto a version that resolves this vulnerability.Fixed in 6.9.7.CU01
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43873?
CVE-2025-43873 has a high severity rating due to the potential for firmware modification and complete device access.
How do I fix CVE-2025-43873?
To mitigate CVE-2025-43873, update the affected Johnson Controls iSTAR devices to versions 6.9.7.CU01 or later.
Which products are affected by CVE-2025-43873?
CVE-2025-43873 affects Johnson Controls iSTAR Ultra, iSTAR Ultra SE, and iSTAR Ultra LT prior to version 6.9.7.CU01.
What can attackers do if they exploit CVE-2025-43873?
Successful exploitation of CVE-2025-43873 allows attackers to modify firmware and gain full access to the affected device.
Is there a specific version that resolves CVE-2025-43873 for the iSTAR Ultra G2?
Yes, updating the iSTAR Ultra G2 to version 6.9.3 resolves the vulnerabilities identified in CVE-2025-43873.