216.73.217.80

CVE-2025-15251

· Published 30/12/2025 14:15 · Modified 31/12/2025 20:42

Labels: CVE-2025-15251 2025-12-30CVE-2025-15251CWE-610[email protected]

Essential information

Published
30/12/2025 14:15
Modified
31/12/2025 20:42
Author
Creator
CVSS
6.3 MEDIUM (v3) 6.3 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability was detected in beecue FastBee up to 2.1. Impacted is the function getRootElement of the file springboot/fastbee-server/sip-server/src/main/java/com/fastbee/sip/handler/req/ReqAbstractHandler.java of the component SIP Message Handler. The manipulation results in xml external entity reference. It is possible to launch the attack remotely. A high complexity level is associated with this attack. The exploitability is considered difficult. The project owner replied to the issue report: "Okay, we'll handle it as soon as possible."

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
beecue / fastbee cpe:2.3:a:beecue:fastbee:*:*:*:*:*:*:*:*

References