CVE-2025-43875: Johnson Controls Istar Ultra, Istar Ultra SE

High severity, CVSS 8.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Under certain circumstances a successful exploitation could result in access to the device.

Affected products

  • Johnson Controls Istar Ultra, Istar Ultra SE: up to and including 6.9.7
  • Johnson Controls Istar Ultra g2, Istar Ultra g2 Se, Istar Edge g2: up to and including 6.9.2

Published 2025-12-24. Last modified 2026-10-07.