CVE-2025-43876: iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection - get8021xSettings
Under certain circumstances a successful exploitation could result in access to the device.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43876?
CVE-2025-43876 is categorized as a high severity vulnerability due to the potential for unauthorized access to the device.
How do I fix CVE-2025-43876?
To mitigate CVE-2025-43876, update Johnson Controls iSTAR Ultra, iSTAR Ultra SE, or iSTAR Ultra G2 versions to at least 6.9.7.CU01 or 6.9.3 respectively.
What devices are affected by CVE-2025-43876?
CVE-2025-43876 affects Johnson Controls iSTAR Ultra, iSTAR Ultra SE, iSTAR Ultra G2, iSTAR Ultra G2 SE, and iSTAR Edge G2 devices.
Can CVE-2025-43876 be exploited remotely?
Yes, under certain circumstances, CVE-2025-43876 can be exploited remotely, allowing potential unauthorized access to the device.
Is there a workaround for CVE-2025-43876 if I cannot update immediately?
Currently, there are no documented workarounds for CVE-2025-43876, and updating the affected software is essential for security.