- Description
- Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability . Successful exploitation of this vulnerability could allow remote SQL execution This issue affects * Metasys: Application and Data Server (ADS) installed with SQL Express deployed as part of the Metasys 14.1 and prior installation, * Extended Application and Data Server (ADX) installed with SQL Express deployed as part of the Metasys 14.1 installation, * LCS8500 or NAE8500 installed with SQL Express deployed as part of the Metasys installation Releases 12.0 through 14.1, * System Configuration Tool (SCT) installed with SQL Express deployed as part of the SCT installation 17.1 and prior, * Controller Configuration Tool (CCT) installed with SQL Express deployed as part of the CCT installation 17.0 and prior.
- Source
- productsecurity@jci.com
- NVD status
- Deferred
CVSS 4.0
- Type
- Secondary
- Base score
- 9.5
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- CRITICAL
- productsecurity@jci.com
- CWE-77
- Hype score
- Not currently trending
Critical SQL injection vulnerability (CVE-2025-26385) found in Johnson Controls products. Immediate action required to protect critical infrastructure. https://t.co/oAixLZ9S8V #Hacking #Vulnerability #CVE #Exploit #Database #Security #Infrastructure #Threat #Protection #Risk http
@dailytechonx
2 Feb 2026
59 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Warning: Critical vulnerability in #Johnson Controls (Metasys SQL Express) allows remote command injection leading to arbitrary SQL execution. #CVE-2025-26385 CVSS: 9.5. Mitigations available at: https://t.co/a9pmv24TM0. #RCE! #Patch #Patch #Patch
@CCBalert
2 Feb 2026
135 Impressions
1 Retweet
2 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ Critical Johnson Controls Vulnerability Critical SQL injection (CVE-2025-26385) hits Johnson Controls products. Remote attackers can steal or alter data. CISA urges isolation & patching. 🔗 https://t.co/92EqGPZw41 #CyberSecurity #ICS #SQLInjection #CISA #Johnso
@VaultEdgeIT
2 Feb 2026
50 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 Critical Johnson Controls ICS Flaw (CVE-2025-26385) Enables Unauthenticated Remote SQL Injection (CVSS 10.0) A critical unauthenticated SQL injection vulnerability (CVE-2025-26385, CVSS 10.0) impacts multiple Johnson Controls ICS products (ADS/ADX, LCS8500, NAE8500, SCT,
@ThreatSynop
1 Feb 2026
85 Impressions
0 Retweets
1 Like
1 Bookmark
0 Replies
0 Quotes
ジョンソンコントロールズ社の複数の産業用制御システム製品において、極めて重大なSQLインジェクションの脆弱性(CVE-2025-26385)が報告されました。この脆弱性の深刻度を示すCVSS
@omomuki_tech
1 Feb 2026
67 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-26385 Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability . Successful exp… https://t.co/fO0RRWqJos
@CVEnew
30 Jan 2026
164 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes