CVE-2025-12001

Severity CVSS v4.0:
CRITICAL
Type:
CWE-20 Input Validation
Publication date:
20/10/2025
Last modified:
07/11/2025

Description

Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:azure-access:blu-ic2_firmware:*:*:*:*:*:*:*:* 1.20 (excluding)
cpe:2.3:h:azure-access:blu-ic2:*:*:*:*:*:*:*:*
cpe:2.3:o:azure-access:blu-ic4_firmware:*:*:*:*:*:*:*:* 1.20 (excluding)
cpe:2.3:h:azure-access:blu-ic4:*:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools