CVE-2025-12552
CRITICALDescription
Insufficient Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
Is your site exposed to CVE-2025-12552?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| azure-access | blu-ic2_firmware |
| azure-access | blu-ic2 |
| azure-access | blu-ic4_firmware |
| azure-access | blu-ic4 |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-12552? +
How severe is CVE-2025-12552? +
What products are affected by CVE-2025-12552? +
How do I check if I'm vulnerable to CVE-2025-12552? +
Related Vulnerabilities
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through …
KTM System e-BOK enforces a maximum password length of six numeric digits and does not permit the use of any …
Hikvision Streaming Media Management Server v2.3.5 uses default credentials that allow remote attackers to authenticate and access restricted functionality. After …
No password for the root user is set in Novakon P series. This allows phyiscal attackers to enter the console …
Victure RX1800 EN_V1.0.0_r12_110933 was discovered to utilize a weak default password which includes the last 8 digits of the Mac …
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.