CISA Issues Five New ICS Advisories on Emerging Vulnerabilities and Exploits
On Tue, Dec 2, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released five critical advisories addressing high-severity vulnerabilities in industrial control systems from multiple vendors.
On Tue, Dec 2, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released five critical advisories addressing high-severity vulnerabilities in industrial control systems from multiple vendors.
The advisories cover vulnerabilities in video surveillance platforms, intelligent metering gateways, medical imaging software, and manufacturing control systems. These vulnerabilities impact critical infrastructure sectors globally, including energy, healthcare, and water systems.
Industrial Video & Control's Longwatch System: A code injection vulnerability identified as CVE-2025-13658 affects versions 6.309 to 6.334. It has a CVSS v4 score of 9.3, allowing remote code execution via unprotected HTTP GET requests. Industrial Video & Control advises upgrading to version 6.335 or later. Iskra's iHUB and iHUB Lite Devices: These devices have a missing authentication vulnerability (CVE-2025-13510, CVSS v4 9.3), affecting all versions. The vulnerability allows unauthorized reconfiguration of devices. Mirion Medical's EC2 Software NMIS BioDose: Five vulnerabilities (CVSS v4 8.7) affect versions prior to 23.0. They include issues with file permissions, hardcoded credentials, unmasked password fields, and unrestricted database privileges. An upgrade to version 23.0 or later is recommended. Mitsubishi Electric CNC Series Tools: An uncontrolled search path element vulnerability (CVE-2016-2542, CVSS v3 7.0) exists in multiple tools. This allows DLL hijacking. Fixed versions are available for some tools. Mitsubishi Electric's MELSEC iQ-R and iQ-F Series: Four vulnerabilities (CVSS v4 8.7) include authentication bypass via FTP functions. Mitigations include network segmentation and firewall protections.
These vulnerabilities impact critical infrastructure sectors globally, including energy, healthcare, and water systems.
CISA recommends defense-in-depth strategies, such as isolating control systems with firewalls, restricting internet exposure, and using VPNs for remote access. No active exploitations have been reported, offering a window for remediation.
Based on reporting by GBHackers.
