CVE-2025-12204 describes a heap-based buffer overflow vulnerability in Kamailio 5.5, specifically within the rve_destroy function of the Configuration File Handler. This vulnerability, rated 7.8 HIGH, requires local access and manipulation of configuration files, leading to potential high impact on confidentiality, integrity, and availability. While the exploit has been publicly disclosed, its real-world applicability is debated due to the requirement of config file manipulation, and there is no evidence of active exploitation or readily available exploit tools like Metasploit or Nuclei.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.5.0CPE matchmatch criteria | cpe:2.3:a:kamailio:kamailio:5.5.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.