Vulnerabilities
39 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-12599 | Multiple Devices are Sharing the Same Secrets for SDKSocket (TCP/5000).This issue affects BLU-IC2: Multiple Devices are Sharing the Same Secrets for SDKSocket (TCP/5000).This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. NVD description · AI analysis pending | 10.0 group max | <1% |
| — | ||
| CVE-2025-12553 | Email Server Certificate Verification Disabled.This issue affects BLU-IC2: Email Server Certificate Verification Disabled.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. NVD description · AI analysis pending | 10.0 group max | <1% |
| — | ||
| CVE-2025-12516 +1 in the same advisory: …12517 | Lack of Graceful Error Handling - HTTP 5xx ErrorThis issue affects BLU-IC2: Lack of Graceful Error Handling - HTTP 5xx ErrorThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . NVD description · AI analysis pending | 10.0 group max | <1% |
| — | ||
| CVE-2025-12515 | Systemic Internal Server Errors - HTTP 500 ResponseThis issue affects BLU-IC2: Systemic Internal Server Errors - HTTP 500 ResponseThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . NVD description · AI analysis pending | 10.0 | <1% |
| — | ||
| CVE-2025-12477 | Server Version Disclosure.This issue affects BLU-IC2: Server Version Disclosure.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 . NVD description · AI analysis pending | 10.0 | <1% |
| — | ||
| CVE-2025-12422 | Vulnerable Upgrade Feature (Arbitrary File Write) may lead to obtaining super user permissions on board.This issue affects BLU-IC2: Vulnerable Upgrade Feature (Arbitrary File Write) may lead to obtaining super user permissions on board.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. NVD description · AI analysis pending | 10.0 | <1% |
| — | ||
| CVE-2025-12364 | Weak Password Policy.This issue affects BLU-IC2: Weak Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. NVD description · AI analysis pending | 10.0 group max | <1% |
| — | ||
| CVE-2025-12275 | Mail Configuration File Manipulation + Command Execution.This issue affects BLU-IC2: Mail Configuration File Manipulation + Command Execution.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. NVD description · AI analysis pending | 10.0 group max | <1% |
| — | ||
| CVE-2025-12220 | Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. NVD description · AI analysis pending | 10.0 group max | <1% |
| — | ||
| CVE-2025-12176 | Undocumented administrative accounts were getting created to facilitate access for applications running on board.This issue affects BLU-IC2: Undocumented administrative accounts were getting created to facilitate access for applications running on board.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. NVD description · AI analysis pending | 10.0 | <1% |
| — | ||
| CVE-2025-12104 +1 in the same advisory: …12114 | Outdated and Vulnerable UI Dependencies might potentially lead to exploitation.This issue affects BLU-IC2: Outdated and Vulnerable UI Dependencies might potentially lead to exploitation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. NVD description · AI analysis pending | 10.0 group max | <1% |
| — | ||
| CVE-2025-12031 | HTTP Security Misconfiguration - Lacking Secure and HTTPOnly Attribute may allow reading the sensitive cookies from the javascript contextThis issue affects BLU HTTP Security Misconfiguration - Lacking Secure and HTTPOnly Attribute may allow reading the sensitive cookies from the javascript contextThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2025-12001 | Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: Lack of application manifest sanitation could lead to potential stored XSS.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. NVD description · AI analysis pending | 10.0 | <1% |
| — | ||
| CVE-2025-11925 | Incorrect Content-Type header in one of the APIs (`text/html` instead of `application/json`) replies may potentially allow injection of HTML/JavaScript into rep Incorrect Content-Type header in one of the APIs (`text/html` instead of `application/json`) replies may potentially allow injection of HTML/JavaScript into reply.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. NVD description · AI analysis pending | 10.0 | <1% |
| — | ||
| CVE-2025-11832 | Allocation of Resources Without Limits or Throttling vulnerability in Azure Access Technology BLU-IC2, Azure Access Technology BLU-IC4 allows Flooding.This issu Allocation of Resources Without Limits or Throttling vulnerability in Azure Access Technology BLU-IC2, Azure Access Technology BLU-IC4 allows Flooding.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. NVD description · AI analysis pending | 10.0 | <1% |
| — |