# CVE-2025-53696

## Summary

- **CVE ID:** CVE-2025-53696
- **Severity:** CRITICAL
- **CVSS Score:** 9.3 (CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)
- **CWE:** CWE-494
- **Published:** Jul 28, 2025
- **Last Modified:** Mar 13, 2026

## Description

iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmware parts may contain malicious code. Tested up to firmware 6.9.2, later firmwares are also possibly affected.

## Affected Products

- Johnson Controls, Inc — iSTAR Ultra (0)

## References

- [CNA](https://raw.githubusercontent.com/reidmefirst/vuln-disclosure/refs/heads/main/2025-03.txt)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.10%
- **EPSS Percentile:** 0.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._