Lack of Input Validation in the web UI might lead to potential exploitation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
History

Mon, 10 Nov 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Azure-access
Azure-access blu-ic2
Azure-access blu-ic2 Firmware
Azure-access blu-ic4
Azure-access blu-ic4 Firmware
Weaknesses CWE-79
CPEs cpe:2.3:h:azure-access:blu-ic2:*:*:*:*:*:*:*:*
cpe:2.3:h:azure-access:blu-ic4:*:*:*:*:*:*:*:*
cpe:2.3:o:azure-access:blu-ic2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:azure-access:blu-ic4_firmware:*:*:*:*:*:*:*:*
Vendors & Products Azure-access
Azure-access blu-ic2
Azure-access blu-ic2 Firmware
Azure-access blu-ic4
Azure-access blu-ic4 Firmware
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Tue, 28 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Oct 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Azure Access Technology
Azure Access Technology blu-ic2
Azure Access Technology blu-ic4
Vendors & Products Azure Access Technology
Azure Access Technology blu-ic2
Azure Access Technology blu-ic4

Sun, 26 Oct 2025 16:45:00 +0000

Type Values Removed Values Added
Description Lack of Input Validation in the web UI might lead to potential exploitation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Title Lack of Input Validation
Weaknesses CWE-20
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: azure-access

Published: 2025-10-26T16:21:56.272Z

Updated: 2025-10-28T14:35:55.307Z

Reserved: 2025-10-26T16:18:56.104Z

Link: CVE-2025-12284

cve-icon Vulnrichment

Updated: 2025-10-28T14:35:52.220Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-26T17:15:52.357

Modified: 2025-11-10T14:57:42.463

Link: CVE-2025-12284

cve-icon Redhat

No data.