CVE-2025-12220: Busybox 1.31.1 - Multiple Known Vulnerabilities
Published Oct 25, 2025
·Updated
Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Affected Software
7 affected components
Busybox Busybox
Busybox BLU-IC2<=1.19.5
Busybox BLU-IC4<=1.19.5
All of the following
Azure-access Blu-ic2 Firmware<1.20
Azure-access Blu-ic2
All of the following
Azure-access Blu-ic4 Firmware<1.20
Azure-access Blu-ic4
Event History
Oct 25, 2025
CVE Published
via MITRE·03:53 PM
Data Sourced
via MITRE·03:53 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12220?
The severity of CVE-2025-12220 is considered critical due to multiple known vulnerabilities affecting the affected versions.
2
How do I fix CVE-2025-12220?
To fix CVE-2025-12220, upgrade to a version of BusyBox that is higher than 1.19.5.
3
What systems are affected by CVE-2025-12220?
CVE-2025-12220 affects BusyBox versions up to 1.19.5, specifically BLU-IC2 and BLU-IC4.
4
What types of vulnerabilities are included in CVE-2025-12220?
CVE-2025-12220 includes multiple known vulnerabilities that could potentially lead to remote code execution or denial of service.
5
Is there a workaround for CVE-2025-12220?
Currently, the best workaround for CVE-2025-12220 is to ensure the use of a patched version of BusyBox.