CVE-2025-43873: Johnson Control Istar Ultra, Istar Ultra Se, Istar Ultra g2, Istar Ultra g2 Se, Istar Edge g2

High severity, CVSS 8.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Successful exploitation of these vulnerabilities could allow an attacker to modify firmware and gain full access to the device.

Affected products

  • Johnson Control Istar Ultra, Istar Ultra Se, Istar Ultra g2, Istar Ultra g2 Se, Istar Edge g2: up to and including 6.9.3

Published 2025-12-17. Last modified 2026-06-17.