CVE-2025-12007: Supermicro BMC firmware update validation bypass
Published Jan 16, 2026
·Updated
There is a vulnerability in the Supermicro BMC firmware validation logic at Supermicro MBD-X13SEM-F . An attacker can update the system firmware with a specially crafted image.
Affected Software
1 affected component
Supermicro MBD-X13SEM-F
Event History
Jan 16, 2026
CVE Published
via MITRE·08:39 AM
Data Sourced
via MITRE·08:39 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-12007?
CVE-2025-12007 is classified as a critical vulnerability due to the potential for unauthorized firmware updates.
2
How do I fix CVE-2025-12007?
To mitigate CVE-2025-12007, apply the latest firmware update from Supermicro that addresses this validation bypass issue.
3
Who is affected by CVE-2025-12007?
CVE-2025-12007 affects users of the Supermicro MBD-X13SEM-F motherboard model.
4
What is the nature of CVE-2025-12007?
CVE-2025-12007 is a firmware update validation bypass allowing attackers to install unauthorized firmware.
5
When was CVE-2025-12007 disclosed?
CVE-2025-12007 was disclosed in January 2026.