CVE-2025-12554: Missing Security Headers
Published Oct 31, 2025
·Updated
Missing Security Headers.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Affected Software
6 affected components
BLU IC2<=1.19.5
BLU IC4<=1.19.5
All of the following
Azure-access Blu-ic2 Firmware<1.20
Azure-access Blu-ic2
All of the following
Azure-access Blu-ic4 Firmware<1.20
Azure-access Blu-ic4
Event History
Oct 31, 2025
CVE Published
via MITRE·03:52 PM
Data Sourced
via MITRE·03:52 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12554?
CVE-2025-12554 has a medium severity rating due to the presence of missing security headers.
2
How do I fix CVE-2025-12554?
To fix CVE-2025-12554, implement the appropriate security headers such as Content-Security-Policy and X-Content-Type-Options in your application.
3
Which software versions are affected by CVE-2025-12554?
CVE-2025-12554 affects BLU-IC2 and BLU-IC4 versions up to 1.19.5.
4
Are there any workarounds for CVE-2025-12554?
A temporary workaround for CVE-2025-12554 is to review and harden server configurations to minimize potential exploits until an official patch is applied.
5
Is CVE-2025-12554 a known vulnerability?
Yes, CVE-2025-12554 is a documented vulnerability that has been identified and assigned a unique identifier.