CVE-2025-43876 is a high-severity vulnerability (CVSS 8.7) that, under specific conditions, could grant an authenticated attacker remote access to an affected device. The vulnerability is categorized as a Command Injection (CWE-78), indicating a critical flaw. While no specific affected products are listed, the potential impact includes high confidentiality, integrity, and availability compromise. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Johnson Controls | ISTAR Ultra G2, ISTAR Ultra G2 SE, ISTAR Edge G2 | >= 0, <= 6.9.2CNA affecteddefault unaffected | |
| Johnson Controls | ISTAR Ultra, ISTAR Ultra SE | >= 0, <= 6.9.7CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.