PT-2025-54178 · Fastbee · Fastbee

Lizhuangpengli

·

Published

2025-12-30

·

Updated

2025-12-30

·

CVE-2025-15251

CVSS v3.1

5.6

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions FastBee versions prior to 2.1
Description A flaw exists in the SIP Message Handler component of FastBee, specifically within the getRootElement function located in the file springboot/fastbee-server/sip-server/src/main/java/com/fastbee/sip/handler/req/ReqAbstractHandler.java. This issue allows for XML External Entity (XXE) reference manipulation, potentially enabling remote attacks. The complexity of exploiting this issue is considered high, and exploitability is difficult.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XXE

Weakness Enumeration

Related Identifiers

CVE-2025-15251

Affected Products

Fastbee