CVE-2025-53696: Johnson Controls, Inc Istar Ultra
Critical severity, CVSS 9.3. EPSS: 0.1% chance of exploitation in the next 30 days.
iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmware parts may contain malicious code. Tested up to firmware 6.9.2, later firmwares are also possibly affected.
Affected products
- Johnson Controls, Inc Istar Ultra: up to and including 6.9.2
Published 2025-07-28. Last modified 2026-06-17.