CVE-2025-12216: Malicious / Malformed App can be Installed but not Uninstalled
Published Oct 25, 2025
·Updated
Malicious / Malformed App can be Installed but not Uninstalled/may lead to unavailability.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Affected Software
6 affected components
BLU IC2<=1.19.5
BLU IC4<=1.19.5
All of the following
Azure-access Blu-ic2 Firmware<1.20
Azure-access Blu-ic2
All of the following
Azure-access Blu-ic4 Firmware<1.20
Azure-access Blu-ic4
Event History
Oct 25, 2025
CVE Published
via MITRE·03:33 PM
Data Sourced
via MITRE·03:33 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12216?
CVE-2025-12216 is assessed to potentially disrupt the availability of affected devices.
2
How do I fix CVE-2025-12216?
To mitigate CVE-2025-12216, upgrade the BLU IC2 or IC4 devices to a version beyond 1.19.5.
3
What devices are affected by CVE-2025-12216?
CVE-2025-12216 affects BLU IC2 and BLU IC4 devices running versions up to and including 1.19.5.
4
Can the malicious app be uninstalled due to CVE-2025-12216?
No, CVE-2025-12216 allows malicious or malformed apps to be installed but not uninstalled.
5
What is the potential impact of CVE-2025-12216 on my device?
CVE-2025-12216 may lead to unavailability, affecting the normal operation of the device.