CVE-2025-1225
Published: 12 February 2025
Summary
CVE-2025-1225 is a medium-severity Externally Controlled Reference to a Resource in Another Sphere (CWE-610) vulnerability in R1Bbit Yimioa. Its CVSS base score is 5.3 (Medium).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked in the top 45.9% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-2088
Vulnerability details
A vulnerability, which was classified as problematic, has been found in ywoa up to 2024.07.03. This issue affects the function extract of the file c-main/src/main/java/com/redmoon/weixin/aes/XMLParse.java of the component WXCallBack Interface. The manipulation leads to xml external entity reference. The attack…
more
may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2024.07.04 is able to address this issue. It is recommended to upgrade the affected component.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
XXE vulnerability (CWE-611) in public-facing WeChat callback interface enables remote exploitation of public-facing application (T1190), arbitrary local file disclosure for data collection (T1005), and reading unsecured credentials from files (T1552.001).
Affected Assets
Mitigating Controls
Likely Mitigating Controls AI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
Penetration testing includes XML external entity payloads, detecting XXE vulnerabilities and enabling their mitigation.
Limits impact of an externally controlled reference to a primary information resource by switching to an identified alternative.
Identifies XML external entity processing via monitoring of unusual file/network access or resource usage.