CVE-2025-12603: /etc/timezone can be Arbitrarily Written
Published Nov 1, 2025
·Updated
/etc/timezone can be Arbitrarily Written.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Affected Software
6 affected components
BLU IC2<=1.19.5
BLU IC4<=1.19.5
All of the following
Azure-access Blu-ic2 Firmware<1.20
Azure-access Blu-ic2
All of the following
Azure-access Blu-ic4 Firmware<1.20
Azure-access Blu-ic4
Event History
Nov 1, 2025
CVE Published
via MITRE·06:56 PM
Data Sourced
via MITRE·06:56 PM
DescriptionWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12603?
CVE-2025-12603 is considered to have a medium severity due to its potential impact on system integrity.
2
How do I fix CVE-2025-12603?
To fix CVE-2025-12603, upgrade to BLU-IC2 or BLU-IC4 versions later than 1.19.5.
3
What software is affected by CVE-2025-12603?
CVE-2025-12603 affects BLU-IC2 and BLU-IC4 versions up to and including 1.19.5.
4
What does CVE-2025-12603 vulnerability allow?
CVE-2025-12603 allows arbitrary writing to the /etc/timezone file, which can lead to misconfiguration.
5
When was CVE-2025-12603 disclosed?
CVE-2025-12603 was disclosed as a vulnerability affecting specific versions of BLU's software.