PT-2025-31108 · Unknown · Istar Ultra

Published

2025-07-28

·

Updated

2025-07-31

·

CVE-2025-53695

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions iSTAR Ultra products (affected versions not specified)
Description An OS Command Injection issue exists in the iSTAR Ultra products web application. An authenticated attacker can exploit this to gain privileged access, specifically 'root' user access, to the device firmware.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-53695

Affected Products

Istar Ultra