CVE-2025-12176
CRITICALDescription
Undocumented administrative accounts were getting created to facilitate access for applications running on board.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| azure-access | blu-ic2_firmware |
| azure-access | blu-ic2 |
| azure-access | blu-ic4_firmware |
| azure-access | blu-ic4 |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-12176? +
How severe is CVE-2025-12176? +
What products are affected by CVE-2025-12176? +
How do I check if I'm vulnerable to CVE-2025-12176? +
Related Vulnerabilities
DBLTek GoIP devices (models GoIP 1, 4, 8, 16, and 32) contain an undocumented vendor backdoor in the Telnet administrative …
Denver SHO-110 IP cameras expose a secondary HTTP service on TCP port 8001 that provides access to a '/snapshot' endpoint …
CWE-1242: Inclusion of Undocumented Features
Inclusion of undocumented features issue exists in UD-LT2 firmware Ver.1.00.008_SE and earlier. A remote attacker may disable the LAN-side firewall …
Inclusion of undocumented features or chicken bits issue exists in UD-LT1 firmware Ver.2.1.8 and earlier and UD-LT1/EX firmware Ver.2.1.8 and …
Inclusion of undocumented features or chicken bits issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions …