CVE-2025-12422: Vulnerable Upgrade Feature (Arbitrary File Write)
Published Oct 28, 2025
·Updated
Vulnerable Upgrade Feature (Arbitrary File Write) may lead to obtaining super user permissions on board.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Affected Software
6 affected components
BLU BLU-IC2<1.19.5
BLU BLU-IC4<1.19.5
All of the following
Azure-access Blu-ic2 Firmware<1.20
Azure-access Blu-ic2
All of the following
Azure-access Blu-ic4 Firmware<1.20
Azure-access Blu-ic4
Event History
Oct 28, 2025
CVE Published
via MITRE·06:09 PM
Data Sourced
via MITRE·06:09 PM
DescriptionWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12422?
CVE-2025-12422 is a critical vulnerability that can lead to arbitrary file write and potentially grant super user permissions.
2
How do I fix CVE-2025-12422?
To fix CVE-2025-12422, users should upgrade their BLU-IC2 and BLU-IC4 devices to versions beyond 1.19.5.
3
Which devices are affected by CVE-2025-12422?
CVE-2025-12422 affects BLU-IC2 and BLU-IC4 models up to version 1.19.5.
4
What type of vulnerability is CVE-2025-12422?
CVE-2025-12422 is classified as an arbitrary file write vulnerability due to a vulnerable upgrade feature.
5
Can CVE-2025-12422 be exploited remotely?
Yes, CVE-2025-12422 can potentially be exploited remotely under certain conditions, allowing attackers to gain elevated privileges.