CVE-2025-11925
MEDIUMDescription
Incorrect Content-Type header in one of the APIs (`text/html` instead of `application/json`) replies may potentially allow injection of HTML/JavaScript into reply.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Is your site exposed to CVE-2025-11925?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| azure-access | blu-ic2_firmware |
| azure-access | blu-ic2 |
| azure-access | blu-ic4_firmware |
| azure-access | blu-ic4 |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-11925? +
How severe is CVE-2025-11925? +
What products are affected by CVE-2025-11925? +
How do I check if I'm vulnerable to CVE-2025-11925? +
Related Vulnerabilities
An unauthenticated remote attacker is able to exhaust all available TCP connections in the CODESYS EtherNet/IP adapter stack, preventing legitimate …
A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user …
A Denial of Service (DoS) vulnerability in Palo Alto Networks PAN-OS software causes the firewall to unexpectedly reboot when processing …
A denial-of-service (DoS) vulnerability in the Simple Certificate Enrollment Protocol (SCEP) authentication feature of Palo Alto Networks PAN-OS® software enables …
An improper exception check in Palo Alto Networks Prisma Access Browser allows a low privileged user to prevent Prisma Access …
ethereum is a common ethereum structs for Rust. Prior to ethereum crate v0.18.0, signature malleability (according to EIP-2) was only …