THREAT OPS › Threat News › Have you patched? Are you sure? The story of the sticky Supermicro BMC bugs
Have you patched? Are you sure? The story of the sticky Supermicro BMC bugs
After repeatedly bypassing Supermicro's BMC firmware validation fixes, we detail CVE-2025-12006 and CVE-2025-12007 — the latest in a year-long chain of vulnerabilities that allowed persistent arbitrary code execution through manipulated firmware update images. We walk through each bypass technique, analyze the final patches, and assess whether these critical issues are truly resolved.
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- CVE-2025-12006cve
- CVE-2025-12007cve