CVE-2025-12422CRITICAL 9.8EPSS p32.1%

CVE-2025-12422CVE-2025-12422

Description

Vulnerable Upgrade Feature (Arbitrary File Write) may lead to obtaining super user permissions on board.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.40% probability of exploitation · percentile 32.1% · 2026-06-19T12:03:05Z
Published2025-10-28
Last modified2025-11-07

Underlying weaknesses· 1

CWE-22

References

  1. https://azure-access.com/security-advisories

1

TypeTargetConfidenceTier
WeaknessImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')cwe-220%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-12424
CVE
CVE-2025-12176
CVE
CVE-2025-12220
CVE
CVE-2025-12221
CVE
CVE-2025-12602
CVE
CVE-2025-12218
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.