Vulnerability Description
Micro Registration Utility (µURU) is a telephone self registration utility based on asterisk. In versions up to and including commit 88db9a953f38a3026bcd6816d51c7f3b93c55893, an attacker can crafts a special federation name and characters treated special by asterisk can be injected into the `Dial( )` application due to improper input validation. This allows an attacker to redirect calls on both of the federating instances. If the attack succeeds, the impact is very high. However, the requires that an admin accept the federation requests. As of time of publication, a known patched version of µURU is not available.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://docs.asterisk.org/Latest_API/API_Documentation/Dialplan_Applications/Dia
- https://github.com/olell/uURU/security/advisories/GHSA-xvrh-pm3f-79v4
FAQ
What is CVE-2025-69205?
CVE-2025-69205 is a vulnerability with a CVSS score of 6.3 (MEDIUM). Micro Registration Utility (µURU) is a telephone self registration utility based on asterisk. In versions up to and including commit 88db9a953f38a3026bcd6816d51c7f3b93c55893, an attacker can crafts a ...
How severe is CVE-2025-69205?
CVE-2025-69205 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-69205?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.