CVE-2025-12479: Systemic Lack of Cross-Site Request Forgery (CSRF) Token Implementation
Published Oct 29, 2025
·Updated
Systemic Lack of Cross-Site Request Forgery (CSRF) Token Implementation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
Affected Software
6 affected components
BLU IC2<1.19.5
BLU IC4<1.19.5
All of the following
Azure-access Blu-ic2 Firmware<1.20
Azure-access Blu-ic2
All of the following
Azure-access Blu-ic4 Firmware<1.20
Azure-access Blu-ic4
Event History
Oct 29, 2025
CVE Published
via MITRE·04:50 PM
Data Sourced
via MITRE·04:50 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12479?
CVE-2025-12479 is considered a high-severity vulnerability due to the risk of unauthorized actions through CSRF attacks.
2
How do I fix CVE-2025-12479?
To fix CVE-2025-12479, implement Cross-Site Request Forgery (CSRF) tokens in your application forms and state-changing requests.
3
What products are affected by CVE-2025-12479?
CVE-2025-12479 affects the BLU-IC2 and BLU-IC4 products up to version 1.19.5.
4
What is a Cross-Site Request Forgery (CSRF) attack?
A Cross-Site Request Forgery (CSRF) attack tricks the user into performing actions on a web application without their consent.
5
What are the consequences of not addressing CVE-2025-12479?
Not addressing CVE-2025-12479 may lead to unauthorized data modifications and security breaches in affected applications.