← back
CVE-2025-12516criticalCWE-394

Lack of Graceful Error Handling - HTTP 5xx Error

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 10epss 0.3%
exploitation probability
0.3%top 73% of all CVEs
observed exploitation
nono source reports it
In short

The BLU-IC2 and BLU-IC4 devices fail to handle server errors gracefully, returning raw HTTP 5xx errors that expose internal system details to attackers. This allows unauthorized disclosure of sensitive information about the device's internal structure and operation.

Technical detail

The affected BLU-IC2 (≤1.19.5) and BLU-IC4 (≤1.19.5) devices lack proper error handling for server-side failures, resulting in unfiltered HTTP 5xx responses that leak internal implementation details. An unauthenticated remote attacker can trigger these errors through normal requests to obtain information useful for further exploitation. The absence of error sanitization creates an information disclosure vulnerability enabling reconnaissance.

Summary generated and translated by AI from the official description.
Lack of Graceful Error Handling - HTTP 5xx ErrorThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H