CVE-2025-26385 describes a critical command injection vulnerability (CWE-77) in various Johnson Controls Metasys components, including ADS, ADX, LCS8500/NAE8500, SCT, and CCT, when installed with SQL Express. This flaw allows for remote SQL execution due to improper neutralization of special elements in commands. With a CVSS score of 9.5 (CRITICAL), the vulnerability is easily exploitable over the network with low attack complexity and no user interaction, leading to high impacts on confidentiality, integrity, and availability. While no public exploit code or active exploitation has been observed, and community discussion is minimal, its high FAUCET Risk Score of 95/100 indicates significant potential danger.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Johnson Controls | Metasys | Application and Data Server (ADS) installed with SQL Express deployed as part of the Metasys 14.1 and prior installation, Controller Configuration Tool (CCT) installed with SQL Express deployed as part of the CCT installation 17.0 and prior, Extended Application and Data Server (ADX) installed with SQL Express deployed as part of the Metasys 14.1 installation, LCS8500 or NAE8500 installed with SQL Express deployed as part of the Metasys installation Releases 12.0 through 14.1, System Configuration Tool (SCT) installed with SQL Express deployed as part of the SCT installation 17.1 and priorCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.