CVE-2025-12600 is a critical vulnerability affecting Azure BLU-IC2 and BLU-IC4 devices running firmware versions up to 1.19.5, where a web UI malfunction can be triggered by setting an unexpected locale via the API. This unauthenticated remote vulnerability carries a CVSS score of 9.8, indicating a high potential for complete compromise of confidentiality, integrity, and availability. While there are no known public exploits or Metasploit/Nuclei modules, the vulnerability has garnered some community discussion, with a recent post highlighting the lack of a patch and recommending restricting admin access and monitoring for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.20CPE matchmatch criteria | cpe:2.3:o:azure-access:blu-ic2_firmware:*:*:*:*:*:*:*:* | ||
< 1.20CPE matchmatch criteria | cpe:2.3:o:azure-access:blu-ic4_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.