CVE-2025-12176
Undocumented administrative accounts were getting created to facilitate access for applications running on board.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 0.32%
- CWE
- CWE-1242
- Published
- 2025-10-24
- Last modified
- 2026-03-13
Affected products
- Azure Access Technology BLU-IC2
- Azure Access Technology BLU-IC4
Weakness type
Related vulnerabilities
- CVE-2023-3634 — Festo: MSE6-C2M/D2M/E2M Incomplete User Documentation of Remote Accessible Functions
- CVE-2025-41756 — Arbitrary Write with ubr-editfile
- CVE-2025-41754 — Arbitrary Read with ubr-editfile
- CVE-2026-24714 — Some end of service NETGEAR products provide "TelnetEnable" functionality, which allows a magic...
- CVE-2021-4469 — Denver SHO-110 IP Camera Unauthenticated Snapshot Access
- CVE-2017-20204 — DBLTek GoIP Telnet Admin Interface Undocumented Backdoor
- CVE-2025-55050 — CWE-1242: Inclusion of Undocumented Features
- CVE-2025-52548 — Enabling SSH and Shellinabox on the vulnerable machine