CVE-2025-53695

CRITICAL

iSTAR Ultra < 6.9.2 - Authenticated OS Command Injection

Title source: llm
STIX 2.1

Description

OS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileged access ('root' user) to the device firmware.

Scores

CVSS v4 9.4
EPSS 0.0092
EPSS Percentile 55.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
Johnson Controls, Inc/iSTAR Ultra < 6.9.2
Published Jul 28, 2025
Tracked Since Feb 18, 2026