Firmware Verification Flaw in iSTAR Ultra by iSTAR Networking
CVE-2025-53696

9.3CRITICAL

Key Information:

Vendor
CVE Published:
28 July 2025

What is CVE-2025-53696?

The iSTAR Ultra firmware verification process at boot time lacks thorough inspection, omitting crucial sections of the firmware that could harbor malicious code. This oversight potentially compromises the integrity of the system, allowing for unauthorized code execution. The vulnerability has been tested up to firmware version 6.9.2, with subsequent versions possibly affected, highlighting the need for stringent security measures in firmware validation.

Affected Version(s)

iSTAR Ultra Linux 0 <= 6.9.2

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53696 : Firmware Verification Flaw in iSTAR Ultra by iSTAR Networking