CVE-2025-53696: Critical severity iSTAR Ultra vulnerability
iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmware parts may contain malicious code. Tested up to firmware 6.9.2, later firmwares are also possibly affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53696?
CVE-2025-53696 is rated as a high-severity vulnerability due to its potential to allow malicious code execution in unverified firmware.
How do I fix CVE-2025-53696?
To mitigate CVE-2025-53696, upgrade your iSTAR Ultra firmware to the latest version available that addresses this vulnerability.
What products are affected by CVE-2025-53696?
CVE-2025-53696 affects iSTAR Ultra devices running firmware version 6.9.2 or earlier.
What is the impact of CVE-2025-53696?
The impact of CVE-2025-53696 includes the potential execution of malicious code from unverified portions of the firmware.
When was CVE-2025-53696 disclosed?
CVE-2025-53696 was disclosed in March 2025.