PatchSiren cyber security CVE debrief
CVE-2025-26379 Johnson Controls Inc. CVE debrief
A weak pseudo-random number generator in Johnson Controls PowerG, IQPanel, and IQHub products allows attackers to read or inject encrypted PowerG packets. The vulnerability affects wireless security communications, with adjacent network access sufficient for exploitation. CISA published the initial advisory on December 16, 2025, with an update on March 5, 2026 that refined the vulnerability description and added mitigation details.
- Vendor
- Johnson Controls Inc.
- Product
- PowerG
- CVSS
- HIGH 7.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-12-16
- Original CVE updated
- 2026-03-05
- Advisory published
- 2025-12-16
- Advisory updated
- 2026-03-05
Who should care
Organizations using Johnson Controls PowerG-enabled security panels (IQPanel 2, IQPanel 2+, IQPanel 4, IQHub) for physical security and access control systems, particularly in critical infrastructure, commercial facilities, and government installations where wireless sensor integrity is essential.
Technical summary
The PowerG wireless protocol implementation uses a cryptographically weak pseudo-random number generator that enables attackers with adjacent network access to predict or manipulate cryptographic material. This allows decryption of captured packets and injection of malicious packets into the encrypted PowerG communication stream. The vulnerability is exploitable without authentication or user interaction.
Defensive priority
HIGH
Recommended defensive actions
- Update IQPanel 4 to firmware version 4.6.1/4.6.1i or later before enrolling any devices
- Upgrade PowerG+ devices to PowerG v53.05 or later
- Enter PIN codes during sensor enrollment and restrict physical access to authorized personnel only
- Replace end-of-life products (IQ Panel 2, IQ Panel 2+, IQ Hub) with IQ Panel 4 running firmware 4.6.1 or greater
- Ensure only trusted devices are permitted on the wireless network
- Review Johnson Controls Product Security Advisory JCI-PSA-2025-01 v2 for detailed mitigation instructions
Evidence notes
CISA CSAF source identifies the root cause as CWE-338 (Use of Cryptographically Weak PRNG). The CVSS 3.1 vector (AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L) indicates adjacent network access is required with high impact to integrity. The March 5, 2026 update added specific firmware version requirements and expanded vendor advisory references.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-26379 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-26379
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-26379 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-26379
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-350-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-350-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.