CVE-2025-12552: Insufficient Password Policy
Published Oct 31, 2025
·Updated
Insufficient Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Affected Software
6 affected components
BLU IC2<=1.19.5
BLU IC4<=1.19.5
All of the following
Azure-access Blu-ic2 Firmware<1.20
Azure-access Blu-ic2
All of the following
Azure-access Blu-ic4 Firmware<1.20
Azure-access Blu-ic4
Event History
Oct 31, 2025
CVE Published
via MITRE·03:43 PM
Data Sourced
via MITRE·03:43 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12552?
CVE-2025-12552 is classified as having a moderate severity due to its potential to allow unauthorized access.
2
How do I fix CVE-2025-12552?
To fix CVE-2025-12552, implement a stronger password policy and update to a secure version of BLU IC2 or IC4 beyond 1.19.5.
3
Which versions are affected by CVE-2025-12552?
CVE-2025-12552 affects BLU-IC2 and BLU-IC4 versions through 1.19.5.
4
What kind of vulnerability is CVE-2025-12552?
CVE-2025-12552 is an Insufficient Password Policy vulnerability.
5
Is CVE-2025-12552 being actively exploited?
At this time, there are no confirmed reports of exploitation related to CVE-2025-12552.