CVE-2025-43875: iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection - getOptionsInfo
Published Dec 24, 2025
·Updated
Under certain circumstances a successful exploitation could result in access to the device.
Affected Software
5 affected componentsFixes available
: Johnson Controls Inc. iSTAR Ultra: Versions prior to 6.9.7.CU01
: Johnson Controls Inc. iSTAR Ultra SE: Versions prior to 6.9.7.CU01
: Johnson Controls Inc. iSTAR Ultra G2<6.9.3
6.9.3
: Johnson Controls Inc. iSTAR Ultra G2 SE<6.9.3
6.9.3
: Johnson Controls Inc. iSTAR Edge G2<6.9.3
6.9.3
Remediation
Information
* Upgrade iSTAR Ultra, iSTAR Ultra SE to version 6.9.7.CU01 or greater.
* Upgrade iSTAR Ultra G2, iSTAR Ultra G2 SE, iSTAR Edge G2 to version 6.9.3 or greater
Event History
Dec 24, 2025
CVE Published
via MITRE·03:19 PM
Data Sourced
via MITRE·03:19 PM
RemedyDescriptionWeakness
Data Sourced
via ICS·03:27 PM
SeverityWeaknessAffected Software
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-43875?
CVE-2025-43875 is considered a high severity vulnerability due to its potential to allow authenticated attackers to gain privileged access to the device.
2
How do I fix CVE-2025-43875?
To fix CVE-2025-43875, update affected products to at least version 6.9.7.CU01 or 6.9.3 as applicable.
3
Which products are affected by CVE-2025-43875?
CVE-2025-43875 affects Johnson Controls iSTAR Ultra, iSTAR Ultra SE, iSTAR Ultra G2, iSTAR Ultra G2 SE, and iSTAR Edge G2 versions prior to 6.9.7.CU01 or 6.9.3.
4
What type of access does CVE-2025-43875 provide?
CVE-2025-43875 can allow authenticated attackers to gain root access to the affected device.
5
Is CVE-2025-43875 exploitable in all environments?
No, CVE-2025-43875 is exploitable under certain circumstances that depend on the configuration and authentication of the web application.