Title: Johnson Controls PowerG, IQPanel and IQHub Vulnerabilities Release Date: December 16, 2025 Alert Code: ICSA-25-350-02 Affected Products and Versions: - PowerG (CVE-2025-61738, CVE-2025-61739, CVE-2025-26379, CVE-2025-61740) - IQHub (CVE-2025-61738, CVE-2025-61739, CVE-2025-26379, CVE-2025-61740) - IQPanel 2 (CVE-2025-61738, CVE-2025-61739, CVE-2025-26379, CVE-2025-61740) - IQPanel 2+ (CVE-2025-61738, CVE-2025-61739, CVE-2025-26379, CVE-2025-61740) - IQPanel 4 (CVE-2025-61738, CVE-2025-61739, CVE-2025-26379, CVE-2025-61740) Related Topics: Industrial Control System Vulnerabilities, Industrial Control Systems Vulnerabilities: - Cleartext Transmission of Sensitive Information - Reusing a Nonce, Key Pair in Encryption - Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) - Origin Validation Error CVSS: v3 7.6 Background: - Critical Infrastructure Sectors: Commercial Facilities - Countries/Areas Deployed: Worldwide - Company Headquarters Location: Ireland Acknowledgments: James Chambers and Sultan Qasim Khan of NCC Group Recommended Practices: - Minimize network exposure - Use secure methods for remote access - Perform impact analysis and risk assessment - Implement recommended cybersecurity strategies Revision History: Initial Release Date: 2025-12-16 Legal Notice and Terms of Use: Subject to CISA Notification and Privacy & Use policy. Tags: - Sector: Commercial Facilities Sector - Topics: Industrial Control System Vulnerabilities, Industrial Control Systems