CVE-2025-11925: Incorrect Content-Type Header
Published Oct 17, 2025
·Updated
Incorrect Content-Type header in one of the APIs (text/html instead of application/json) replies may potentially allow injection of HTML/JavaScript into reply.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Affected Software
6 affected components
BLU IC2<=1.19.5
BLU IC4<=1.19.5
All of the following
Azure-access Blu-ic2 Firmware<1.20
Azure-access Blu-ic2
All of the following
Azure-access Blu-ic4 Firmware<1.20
Azure-access Blu-ic4
Event History
Oct 17, 2025
CVE Published
via MITRE·07:56 PM
Data Sourced
via MITRE·07:56 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-11925?
CVE-2025-11925 has a medium severity rating due to the risk of HTML/JavaScript injection.
2
How do I fix CVE-2025-11925?
To fix CVE-2025-11925, ensure that the API correctly sets the Content-Type header to 'application/json'.
3
What products are affected by CVE-2025-11925?
CVE-2025-11925 affects BLU-IC2 and BLU-IC4 up to version 1.19.5.
4
What are the potential risks associated with CVE-2025-11925?
The risks associated with CVE-2025-11925 include the possibility of executing unauthorized scripts and compromising user data.
5
Is there a patch for CVE-2025-11925?
Yes, users should upgrade to versions above 1.19.5 for both BLU-IC2 and BLU-IC4 to mitigate CVE-2025-11925.