CVE-2025-12422

Severity CVSS v4.0:
CRITICAL
Type:
CWE-22 Path Traversal
Publication date:
28/10/2025
Last modified:
07/11/2025

Description

Vulnerable Upgrade Feature (Arbitrary File Write) may lead to obtaining super user permissions on board.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:azure-access:blu-ic2_firmware:*:*:*:*:*:*:*:* 1.20 (excluding)
cpe:2.3:h:azure-access:blu-ic2:*:*:*:*:*:*:*:*
cpe:2.3:o:azure-access:blu-ic4_firmware:*:*:*:*:*:*:*:* 1.20 (excluding)
cpe:2.3:h:azure-access:blu-ic4:*:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools