Cyber Posture

CVE-2025-12285

Critical

Published: 26 October 2025

Published
26 October 2025
Modified
10 November 2025
KEV Added
Patch
CVSS Score 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0009 26.1th percentile
Risk Priority 20 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.

Security Summary

CVE-2025-12285 is a critical vulnerability involving missing initial password change, published on 2025-10-26. It affects BLU-IC2 through version 1.19.5 and BLU-IC4 through version 1.19.5. The issue is linked to CWE-20 (Improper Input Validation) and CWE-521 (Weak Password Requirements), earning a CVSS v3.1 base score of 9.8 due to its network accessibility, low attack complexity, lack of required privileges or user interaction, and high impacts on confidentiality, integrity, and availability.

Remote attackers require no authentication or privileges to exploit this vulnerability over the network. Successful exploitation allows attackers to gain high-level access, potentially compromising the full confidentiality, integrity, and availability of affected BLU-IC2 or BLU-IC4 devices by leveraging unchanged default or weak initial passwords.

For mitigation details, refer to the security advisory at https://azure-access.com/security-advisories.

Details

CWE(s)
CWE-20CWE-521

Affected Products

azure-access
blu-ic2 firmware
≤ 1.20
azure-access
blu-ic4 firmware
≤ 1.20

MITRE ATT&CK Enterprise Techniques

T1078.001 Default Accounts Stealth
Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
Why these techniques?

The vulnerability involves unchanged default or weak initial passwords allowing unauthenticated remote access to high-level privileges, directly facilitating use of default accounts (T1078.001).

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

References