CVE-2025-12031: HTTP Security Misconfiguration - Lacking Secure and HTTPOnly Attribute
Published Oct 21, 2025
·Updated
HTTP Security Misconfiguration - Lacking Secure and HTTPOnly Attribute may allow reading the sensitive cookies from the javascript contextThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Affected Software
6 affected components
BLU IC2<=1.19.5
BLU IC4<=1.19.5
All of the following
Azure-access Blu-ic2 Firmware<1.20
Azure-access Blu-ic2
All of the following
Azure-access Blu-ic4 Firmware<1.20
Azure-access Blu-ic4
Event History
Oct 21, 2025
CVE Published
via MITRE·05:22 PM
Data Sourced
via MITRE·05:22 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12031?
CVE-2025-12031 is considered a high severity vulnerability due to the risk of sensitive cookie exposure.
2
How do I fix CVE-2025-12031?
To fix CVE-2025-12031, ensure that the Secure and HTTPOnly attributes are properly configured on your cookies.
3
Which versions are affected by CVE-2025-12031?
CVE-2025-12031 affects BLU-IC2 and BLU-IC4 versions up to and including 1.19.5.
4
What are the risks of CVE-2025-12031?
The risks of CVE-2025-12031 include potential unauthorized access to sensitive information stored in cookies through JavaScript.
5
Is CVE-2025-12031 in use currently?
Yes, CVE-2025-12031 is in use and impacts applications that have not updated to secure cookie configurations.