CVE-2025-12001: Incorrect Content-Type Header
Published Oct 20, 2025
·Updated
Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Affected Software
6 affected components
BLU BLU-IC2<1.19.5
BLU BLU-IC4<1.19.5
All of the following
Azure-access Blu-ic2 Firmware<1.20
Azure-access Blu-ic2
All of the following
Azure-access Blu-ic4 Firmware<1.20
Azure-access Blu-ic4
Event History
Oct 20, 2025
CVE Published
via MITRE·09:53 PM
Data Sourced
via MITRE·09:53 PM
DescriptionWeakness
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12001?
CVE-2025-12001 is classified as a moderate vulnerability due to the risk of stored cross-site scripting (XSS).
2
How do I fix CVE-2025-12001?
To fix CVE-2025-12001, update the affected BLU-IC2 and BLU-IC4 products to version 1.19.6 or later, which includes sanitization fixes.
3
What versions are affected by CVE-2025-12001?
CVE-2025-12001 affects BLU-IC2 and BLU-IC4 up to version 1.19.5.
4
What impact does CVE-2025-12001 have on users?
CVE-2025-12001 may allow attackers to execute malicious scripts in the browser of users who interact with the affected application.
5
Is there a workaround for CVE-2025-12001?
There is no official workaround for CVE-2025-12001, so applying the update is the recommended solution.