CVE-2025-12425 Details
Description
Local Privilege Escalation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
A local privilege escalation vulnerability exists in BLU-IC2 versions through 1.19.5 and BLU-IC4 versions through 1.19.5. This vulnerability allows users to gain elevated privileges, potentially leading to unauthorized access or control over system resources.
Users are advised to update to the latest version of the firmware or software that is currently supported.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://azure-access.com/security-advisories | azure-access | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | azure-access |
Affected Products
| Product | Versions |
|---|---|
| azure-access blu-ic2 firmware | < 1.20 |
CPE
Remediation
| |
| azure-access blu-ic2 | All versions |
CPE
Remediation
| |
| azure-access blu-ic4 firmware | < 1.20 |
CPE
Remediation
| |
| azure-access blu-ic4 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | azure-access |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 7, 2025 | Initial Analysis | [email protected] |
| Oct 28, 2025 | New CVE Received | azure-access |