← back
CVE-2025-12220criticalCWE-1395

Busybox 1.31.1 - Multiple Known Vulnerabilities

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 10epss 0.3%
exploitation probability
0.3%top 73% of all CVEs
observed exploitation
nono source reports it
In short

Busybox 1.31.1 contains multiple known security vulnerabilities that can be exploited to compromise affected systems. These flaws affect BLU-IC2 and BLU-IC4 devices up to version 1.19.5, potentially allowing attackers to gain unauthorized access or execute malicious code.

Technical detail

This vulnerability encompasses multiple known flaws in Busybox 1.31.1 affecting BLU-IC2 and BLU-IC4 devices through version 1.19.5. The impact allows for potential privilege escalation, arbitrary code execution, or information disclosure depending on the specific vulnerability exploited within the Busybox component. Remediation requires updating affected devices to patched versions beyond 1.19.5.

Summary generated and translated by AI from the official description.
Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H