Cyber Resilience

CVE-2025-25330

Published
27 February 2025
Modified
15 April 2026
CVSS Score v3.1 5.5
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Score 0.0018 8th percentile
Risk Priority 41 floored blend · peak EPSS

Summary

CVE-2025-25330 is a medium-severity Improper Neutralization of Encoded URI Schemes in a Web Page (CWE-84) vulnerability. Its CVSS base score is 5.5 (Medium).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 8th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to SI-10 (Information Input Validation) — see the control section below for these in your framework.

EU & UK References

Vulnerability Data

An issue in Boohee Technology Boohee Health iOS 13.0.13 allows attackers to access sensitive user information via supplying a crafted link.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise Techniques

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
T1659 Content Injection Initial Access
Adversaries may gain access and continuously communicate with victims by injecting malicious content into systems through online network traffic.
T1189 Drive-by Compromise Initial Access
Adversaries may gain access to a system through a user visiting a website over the normal course of browsing.
T1203 Exploitation for Client Execution Execution
Adversaries may exploit software vulnerabilities in client applications to execute code.
Derived from this CVE’s CWE(s) via the direct CWE→ATT&CK cross-walk.

CVEs Like This One

CVE-2025-25329Shared CWE-84
CVE-2025-25326Shared CWE-84
CVE-2025-25334Shared CWE-84
CVE-2025-25325Shared CWE-84
CVE-2024-52890Shared CWE-84
CVE-2025-25331Shared CWE-84
CVE-2024-42184Shared CWE-84
CVE-2025-25323Shared CWE-84
CVE-2025-25324Shared CWE-84
CVE-2025-58444Shared CWE-84

Affected Assets

Mitigating Controls

Mitigating Controls (NIST 800-53 r5) AI

Input validation directly requires checking and neutralizing user-supplied encoded URI schemes before they can be rendered or executed.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

Secure SDLC practices directly require proper input neutralization and output encoding to prevent URI-based injection flaws.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

finds

Security testing in development and acceptance will detect URI-scheme injection flaws before release.

prevents

Secure development life cycle incorporates the above controls, providing indirect but systematic coverage.

prevents

Application security requirements explicitly call for input validation and output encoding that directly prevent URI-scheme injection.

prevents

Secure coding standards mandate proper neutralization of encoded URI schemes, eliminating the root cause of CWE-84.

References