CVE-2025-10821 Overview
CVE-2025-10821 is an improper authorization vulnerability [CWE-266] affecting fuyang_lipengjun platform version 1.0. The flaw resides in the TopicCategoryController function that handles requests to the /topiccategory/queryAll endpoint. An authenticated remote attacker with low privileges can access data returned by this endpoint without the authorization checks the application should enforce. Public disclosure of the exploit technique has been reported by VulDB, increasing the risk that opportunistic actors will attempt to abuse the endpoint. The confidentiality impact is limited, and the vulnerability does not affect integrity or availability.
Critical Impact
Remote low-privileged attackers can invoke the /topiccategory/queryAll endpoint and retrieve topic category data that should be restricted by proper authorization controls.
Affected Products
- fuyang_lipengjun platform 1.0.0
- Component: fuyang_lipengjun:platform
- CPE: cpe:2.3:a:fuyang_lipengjun:platform:1.0.0:*:*:*:*:*:*:*
Discovery Timeline
- 2025-09-22 - CVE-2025-10821 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-10821
Vulnerability Analysis
The vulnerability is classified as improper authorization [CWE-266]. The TopicCategoryController exposes the /topiccategory/queryAll route without validating whether the requesting principal holds the role or permission required to enumerate topic categories. Any authenticated caller can therefore query the endpoint and receive results that should be restricted to privileged users. The exploit path is network-reachable and does not require user interaction. VulDB reports that a working exploit has been published, so administrators should treat the endpoint as actively probed. Impact is scoped to confidentiality of the data returned by the endpoint; the flaw does not enable data modification or service disruption.
Root Cause
The root cause is missing or insufficient authorization enforcement inside the TopicCategoryController.queryAll handler. The controller relies on authentication alone and does not apply role-based access control before returning topic category records. This design deviates from the principle of least privilege and permits horizontal or vertical privilege escalation depending on the intended access model.
Attack Vector
Exploitation requires network access to the platform and a valid low-privilege account. The attacker issues an HTTP request to /topiccategory/queryAll and receives the full list of topic categories regardless of assigned role. No specialized tooling, elevated privileges, or user interaction is required. Because the endpoint is exposed over HTTP, the attack can be performed from any host that can reach the application, including through proxied or tunneled connections.
No verified proof-of-concept code is included in the CVE record. Refer to the VulDB entry #325178 and the CNBlogs security post for published technical details.
Detection Methods for CVE-2025-10821
Indicators of Compromise
- Unexpected HTTP GET or POST requests to /topiccategory/queryAll originating from low-privileged user sessions.
- Repeated enumeration patterns against /topiccategory/* endpoints from a single session or IP address.
- Web server access logs showing successful 200 OK responses to /topiccategory/queryAll for accounts that should not have administrative visibility.
Detection Strategies
- Correlate application access logs with user role assignments to flag queryAll responses served to non-privileged accounts.
- Deploy a WAF rule that inspects requests to /topiccategory/queryAll and validates the caller's session role against an allowlist.
- Add server-side audit logging inside TopicCategoryController to record the authenticated principal for every invocation of queryAll.
Monitoring Recommendations
- Alert on volumetric spikes of requests to /topiccategory/queryAll from a single IP or authenticated session.
- Baseline expected caller identities for administrative endpoints and generate alerts on deviations.
- Forward web application logs to a centralized SIEM and retain them for retrospective hunts against the exposed endpoint.
How to Mitigate CVE-2025-10821
Immediate Actions Required
- Restrict network exposure of the /topiccategory/queryAll endpoint to trusted management networks until a fix is applied.
- Implement server-side role checks in TopicCategoryController.queryAll that validate the caller against required privileges before returning data.
- Rotate credentials for any low-privilege accounts that may have accessed the endpoint and review audit logs for prior enumeration.
Patch Information
No vendor advisory or official patch has been published in the CVE record for fuyang_lipengjun platform 1.0. Track the VulDB CTI entry #325178 for updates and monitor the project's repository for a fixed release. Until a vendor patch is available, apply the code-level and network-level workarounds below.
Workarounds
- Add an authorization filter or interceptor (for example, a Spring HandlerInterceptor or method-level @PreAuthorize) that gates /topiccategory/** routes to administrative roles.
- Place the application behind a reverse proxy that enforces access control lists on the affected URI path.
- Disable the queryAll route if it is not required in production and expose only paginated, role-scoped alternatives.
# Example nginx block restricting /topiccategory/queryAll to an internal admin subnet
location = /topiccategory/queryAll {
allow 10.0.10.0/24; # admin management network
deny all;
proxy_pass http://platform_backend;
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
