CVE-2025-12221: CSRF Token not Properly Implemented
Published Oct 25, 2025
·Updated
Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Affected Software
5 affected components
Busybox Busybox<=1.19.5
All of the following
Azure-access Blu-ic2 Firmware<1.20
Azure-access Blu-ic2
All of the following
Azure-access Blu-ic4 Firmware<1.20
Azure-access Blu-ic4
Event History
Oct 25, 2025
CVE Published
via MITRE·03:57 PM
Data Sourced
via MITRE·03:57 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12221?
CVE-2025-12221 has been classified as a high severity vulnerability due to its multiple known issues in Busybox 1.31.1 and earlier versions.
2
How do I fix CVE-2025-12221?
To resolve CVE-2025-12221, update Busybox to version 1.31.2 or later.
3
What software is affected by CVE-2025-12221?
CVE-2025-12221 affects Busybox versions up to and including 1.19.5.
4
What are the implications of CVE-2025-12221?
CVE-2025-12221 may allow attackers to exploit multiple vulnerabilities within Busybox, potentially leading to unauthorized access or system compromise.
5
Is CVE-2025-12221 being actively exploited?
As of the latest information, there have been no public reports indicating that CVE-2025-12221 is actively being exploited in the wild.