Security is Everyone’s Responsibility

IQHub scaled

Every security system comes with a kind of unspoken trust. We trust the locks to lock, the sensors to report what they detect and the panel to interpret those signals correctly. We also trust that the technology behind them is still being maintained, even though most of us never see that work. When updates stop, the system may continue to look and behave exactly as it always has. What changes is the level of protection behind the screen.

Smart home security panels are easy to overlook once they are mounted and working. They arm doors, communicate with sensors, control connected devices and call for help when something goes wrong. But behind the touchscreen is a computer running software, firmware and wireless protocols. Like any other connected computer, it requires security updates throughout its useful life.

A panel can continue operating long after its manufacturer has stopped developing updates for it. The screen does not display a warning that the product has reached the end of its support life. Determining that requires checking the exact model, installed software and manufacturer advisories. But who is responsible for that?

Sponsored

I wanted to see what that looked like in practice, so I examined one of these panels more closely. From the outside, nothing about it appeared unusual. The important details were buried in its systems information. First, I needed to get into the system admin for advanced settings. The panel still accepted Qolsys’s factory defaulter Dealer code, which I found through a basic internet search. Leaving a publicly documented default credential active means the panel was not property hardened after installation. This code provides access to ALL options. Basic system security depends on how a system is installed and maintained, not simply whether it appears to work after installation. It is much more privileged than an ordinary resident code.

CISA’s guidance is clear that manufacturer default credentials should be changed during installation or commissioning. Leaving the default active suggests the panel was never fully hardened, regardless of who originally installed it.

With physical access and the default Dealer Code, an unauthorized person could gain administrative level control over the panel. That could potentially allow someone to create or change user codes, add or remove sensors, alter entry delays and arming behavior, temporarily disable sirens, change network or system settings, remove connected devices, erase stored information or reset the panel. The result could be security blind spots, false alarms, loss of monitoring, persistent unauthorized access or legitimate users being locked out. These panels have the ability to control other automation devices, so the issue spirals. Think of it as a local privileged access problem.

firmware e1788925446840

The panel examined for this article is an original Qolsys IQ Hub, part number QS9301-0208-840. Qolsys identifies that part number as a PowerG only model using Verizon cellular service. The panel is running software version 3.1.3-ADCS 9.14.5 with build number 20241115_b22. Those details matter because Qolsys states that version 3.1.3 is the last planned firmware release for the IQ Hub⁠.

That does not mean the panel immediately stops working. End of life equipment may continue arming, chiming and communicating with sensors. It means the manufacturer has reached the end of its planned update path. If a new vulnerability is discovered afterward, there may be no supported firmware release available to correct it.

These panels were not designed for a narrow or unusual market. Johnson Controls introduced the IQ Hub for residential properties, small businesses, builders, multifamily developments and wellness installations. The company specifically described it as suitable for lower cost residential and multifamily applications. CISA also identifies the affected equipment as deployed worldwide. In other words, these units may remain installed in homes, apartments, town home communities, managed housing and small commercial properties long after the original installation.

The cybersecurity concern is documented in Johnson Controls advisory JCI PSA 2025 01⁠ and CISA advisory ICSA 25 350 02⁠. Both identify every version of the IQ Hub as affected by four vulnerabilities involving PowerG wireless communications.

CVE-2025-61738 involves sensitive information being transmitted in clear text under certain circumstances, potentially allowing an attacker to capture the network key and read or write encrypted PowerG packets. CVE-2025-61739 involves reuse of a cryptographic nonce, which could allow captured messages to be decrypted or replayed. CVE-2025-26379 involves a weak pseudo random number generator that could allow encrypted packets to be read or injected. CVE-2025-61740 involves inadequate verification of a packet’s source, potentially allowing an attacker to modify device configuration or create a denial of service condition.

powerG

In blunt terms, the key can potentially be exposed, encrypted messages can potentially be decrypted or replayed, the encryption uses weak randomness, and the system may trust packets without adequately verifying who sent them.

That undermines three protections an encrypted security sensor network should provide: confidentiality, authenticity and integrity. The possibility of a denial of service condition also raises an availability concern because a security system must remain operational when it is needed.

The advisory does not prove that any particular panel has been compromised. CISA reports that no known public exploitation specifically targeting these vulnerabilities has been reported. Exploitation also requires the right technical conditions and access. Still, the absence of a known attack does not create a patch for an affected product.

The central problem is straightforward. Qolsys identifies version 3.1.3 as the last planned IQ Hub firmware release. Johnson Controls and CISA list every IQ Hub version as affected. Neither organization identifies a corrected IQ Hub firmware version. Johnson Controls instead identifies the IQ Hub as an end of life product and points customers toward replacement with a supported IQ Panel running firmware version 4.6.1 or later.

For an affected original IQ Hub, repeatedly checking for updates does not resolve the underlying problem. There is no newer supported IQ Hub firmware listed as a fix for these vulnerabilities. The practical remedy is to replace the panel with a currently supported model, confirm that the replacement is running the recommended firmware and verify that every connected sensor has been enrolled securely.

smart home 955059642

Responsible smart home ownership, regardless of living in or renting out the property, requires more than installing attractive technology and paying for monitoring. Property owners, operators and security providers should maintain an inventory of installed panels, record their firmware versions, monitor manufacturer and CISA advisories, track when support ends and budget for replacement before equipment becomes unpatchable.

When a residence is advertised as a smart home, ongoing security maintenance should be part of that promise. A glowing touchscreen is not proof that a system remains secure. If a security panel is affected by known vulnerabilities and no supported update is available, leaving it in service turns the smart home label into marketing instead of meaningful protection.


Discover more from Solide Info | The Engineer’s Authority on Cyber Defense

Subscribe to get the latest posts sent to your email.