CVE-2025-12284: Lack of Input Validation
Published Oct 26, 2025
·Updated
Lack of Input Validation in the web UI might lead to potential exploitation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Affected Software
6 affected components
BLU IC2<=1.19.5
BLU IC4<=1.19.5
All of the following
Azure-access Blu-ic2 Firmware<1.20
Azure-access Blu-ic2
All of the following
Azure-access Blu-ic4 Firmware<1.20
Azure-access Blu-ic4
Event History
Oct 26, 2025
CVE Published
via MITRE·04:21 PM
Data Sourced
via MITRE·04:21 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12284?
CVE-2025-12284 is considered a high severity vulnerability due to the lack of input validation that could be exploited.
2
How do I fix CVE-2025-12284?
To remediate CVE-2025-12284, upgrade BLU-IC2 and BLU-IC4 to version 1.19.6 or later where the input validation issue is resolved.
3
What software is affected by CVE-2025-12284?
CVE-2025-12284 affects BLU-IC2 and BLU-IC4 up to and including version 1.19.5.
4
What could happen if CVE-2025-12284 is exploited?
Exploitation of CVE-2025-12284 could lead to unauthorized actions performed through the web UI.
5
Is there a workaround for CVE-2025-12284?
There are currently no official workarounds for CVE-2025-12284, and upgrading to a fixed version is recommended.