PT-2025-43866 · Kamailio+1 · Kamailio+1

Vuldb

+1

·

Published

2025-10-27

·

Updated

2025-10-28

·

CVE-2025-12206

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Kamailio version 5.5
Description A flaw exists in Kamailio where manipulation of the rve is constant function within the src/core/rvalue.c file can lead to a null pointer dereference. The attack requires local access. The exploit for this issue has been published. The vendor was contacted regarding this disclosure but did not respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Resource Release

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2025-12206

Affected Products

Debian
Kamailio