PT-2025-52650 · Johnson Controls · Iq Panels2+4

James Chambers

+1

·

Published

2025-12-22

·

Updated

2025-12-22

·

CVE-2025-26379

CVSS v4.0

7.2

High

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG (affected versions not specified)
Description The software utilizes a weak pseudo-random number generator. This could allow an attacker to read or inject encrypted PowerG packets.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-26379

Affected Products

Iq Panels 2+
Iq Panels2
Iqhub
Iqpanel 4
Powerg