Critical Johnson Controls Products Vulnerabilities Enables Remote SQL Injection Attacks

A critical advisory addressing a severe SQL injection vulnerability affecting multiple Johnson Controls industrial control system products. The vulnerability, tracked as CVE-2025-26385, carries a maximum CVSS v3 severity score of 10.0, indicating the highest level of risk to affected infrastructure. The flaw stems from improper neutralization of special elements used in command injection, allowing remote […]

The post Critical Johnson Controls Products Vulnerabilities Enables Remote SQL Injection Attacks appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: