CVE-2025-11925

CVE-2025-11925

  • Severity: HIGH
  • CVE: CVE-2025-11925
  • Affected Hardware: BLU-IC2, BLU-IC4
  • Firmware Version: 1.19.5
  • Mitigations: NO
  • Reported by: Kevin Schaller, Benjamin Lafois, Alexi Bitsios, Sebastian Toscano, Dominik Schneider
  • Active exploitation of vulnerability: NO
  • Description: Incorrect Content-Type header in one of the APIs (`text/html` instead of `application/json`) replies may potentially allow injection of HTML/JavaScript into reply.
  • Which versions patch releases are available for: 1.20