CVE-2025-12602: /etc/avahi/services/z9.service can be Arbitrarily Written
Published Nov 1, 2025
·Updated
/etc/avahi/services/z9.service can be Arbitrarily Written.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Affected Software
6 affected components
BLU BLU-IC2<1.19.5
BLU BLU-IC4<1.19.5
All of the following
Azure-access Blu-ic2 Firmware<1.20
Azure-access Blu-ic2
All of the following
Azure-access Blu-ic4 Firmware<1.20
Azure-access Blu-ic4
Event History
Nov 1, 2025
CVE Published
via MITRE·06:54 PM
Data Sourced
via MITRE·06:54 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Sep 25, 57822
Event
via NVD·01:42 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-12602?
The severity of CVE-2025-12602 is considered critical due to the possibility of arbitrary file writing.
2
How do I fix CVE-2025-12602?
To fix CVE-2025-12602, upgrade the BLU-IC2 and BLU-IC4 devices to versions later than 1.19.5.
3
What systems are affected by CVE-2025-12602?
CVE-2025-12602 affects BLU-IC2 and BLU-IC4 devices running versions up to and including 1.19.5.
4
What kind of attack does CVE-2025-12602 allow?
CVE-2025-12602 allows an attacker to perform arbitrary file writes, leading to potential system compromise.
5
Is there a patch available for CVE-2025-12602?
Yes, a patch is available in the updated versions of the affected BLU devices.