Cyber Resilience

CVE-2025-12517

Azure-Access Blu-Ic2 Firmware ≤ 1.20

Published
30 October 2025
Modified
10 November 2025
Patch / advisory
CVSS Score v4 2.1
Click a component to see what it means
Raw vectorCVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score 0.0019 9th percentile
Risk Priority 15 floored blend · peak EPSS

Summary

CVE-2025-12517 is a low-severity Obsolete Feature in UI (CWE-448) vulnerability in Azure-Access Blu-Ic2 Firmware. Its CVSS base score is 2.1 (Low).

Operationally, ranked at the 9th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Credits Page not Matching Versions in Use in the FirmwareThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .

CWE(s)

Related Threats

CVEs Like This One

CVE-2025-11925Same product: Azure-Access Blu-Ic2
CVE-2025-12001Same product: Azure-Access Blu-Ic2
CVE-2025-12285Same product: Azure-Access Blu-Ic2
CVE-2025-12423Same product: Azure-Access Blu-Ic2
CVE-2025-12602Same product: Azure-Access Blu-Ic2
CVE-2025-12284Same product: Azure-Access Blu-Ic2
CVE-2025-12218Same product: Azure-Access Blu-Ic2
CVE-2025-12479Same product: Azure-Access Blu-Ic2
CVE-2025-12364Same product: Azure-Access Blu-Ic2
CVE-2025-12553Same product: Azure-Access Blu-Ic2

Affected Assets

azure-access
blu-ic2 firmware
≤ 1.20
azure-access
blu-ic4 firmware
≤ 1.20

Mitigating Controls

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-02 mostly match
prevents

Maintaining or removing software commensurate with risk directly addresses obsolete UI functions by requiring their replacement or clear user notification.

ID.AM-08 partial match
prevents

Lifecycle management of software includes deprecation processes that would normally require user warnings for obsolete UI features.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

prevents

Secure development lifecycle requires removal or deprecation of obsolete UI features before release.

prevents

Application security requirements can mandate warnings or removal of deprecated UI functions.

prevents

Secure coding standards discourage leaving obsolete UI code without user notification.

finds

Security testing can detect and flag obsolete UI features that lack appropriate warnings.

References