Home

Description

Authentication issue that does not verify the source of a packet which could allow an attacker to create a denial-of-service condition or modify the configuration of the device.

PUBLISHED Reserved 2025-09-30 | Published 2025-12-22 | Updated 2025-12-22 | Assigner jci




HIGH: 7.2CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:N

Problem types

CWE-346 Origin Validation Error

Product status

Default status
unaffected

IQ Panels2 (custom)
affected

IQ Panels2+ (custom)
affected

IQHub (custom)
affected

IQPanel 4 (custom)
affected

PowerG (custom)
affected

Credits

James Chambers of NCC group finder

Sultan Qasim Khan of NCC group finder

References

www.johnsoncontrols.com/...cybersecurity/security-advisories

www.cisa.gov/news-events/ics-advisories/icsa-25-350-02

cve.org (CVE-2025-61740)

nvd.nist.gov (CVE-2025-61740)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.