Writeup Exploits

68,059 exploits tracked across all sources.

Sort: Activity Stars
CVE-2024-34475 WRITEUP HIGH
open5gs < 2.7.1 - Denial of Service via NAS Message Handling in AMF
Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmm_state_authentication in amf/gmm-sm.c for != OGS_ERROR.
CVSS 7.5
CVE-2024-33382 WRITEUP MEDIUM
Open5GS 2.7.0 - Denial of Service via Unsuccessful UE/gnb Registration
An issue in Open5GS v.2.7.0 allows an attacker to cause a denial of service via the 64 unsuccessful UE/gnb registration
CVSS 5.3
CVE-2023-50020 WRITEUP HIGH
open5gs v2.6.6 - Denial of Service via SIGPIPE
An issue was discovered in open5gs v2.6.6. SIGPIPE can be used to crash AMF.
CVSS 7.5
CVE-2023-50019 WRITEUP MEDIUM
open5gs v2.6.6 - Denial of Service via Nudm_UECM_Registration Response Error Handling
An issue was discovered in open5gs v2.6.6. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of Nudm_UECM_Registration response.
CVSS 5.9
CVE-2022-3354 WRITEUP LOW
open5gs < 2.4.10 - Denial of Service in UDP Packet Handler
A vulnerability has been found in Open5GS up to 2.4.10 and classified as problematic. This vulnerability affects unknown code in the library lib/core/ogs-tlv-msg.c of the component UDP Packet Handler. The manipulation leads to denial of service. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-209686 is the identifier assigned to this vulnerability.
CVSS 3.5
CVE-2022-3299 WRITEUP MEDIUM
Open5GS 2.4.0-2.4.10 - Denial of Service in AMF SBI Client
A vulnerability was found in Open5GS up to 2.4.10. It has been declared as problematic. Affected by this vulnerability is an unknown functionality in the library lib/sbi/client.c of the component AMF. The manipulation leads to denial of service. The attack can be launched remotely. The name of the patch is 724fa568435dae45ef0c3a48b2aabde052afae88. It is recommended to apply a patch to fix this issue. The identifier VDB-209545 was assigned to this vulnerability.
CVSS 4.3
CVE-2021-44109 WRITEUP HIGH
open5gs < 2.3.6 - Denial of Service via Crafted SBI Request
A buffer overflow in lib/sbi/message.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request.
CVSS 7.5
CVE-2021-44108 WRITEUP HIGH
Open5GS < 2.3.6 - Denial of Service via Crafted SBI Request to AMF
A null pointer dereference in src/amf/namf-handler.c in Open5GS 2.3.6 and earlier allows remote attackers to Denial of Service via a crafted sbi request to amf.
CVSS 7.5
CVE-2021-44081 WRITEUP HIGH
open5gs 2.1.4 - Denial of Service via MSIN Length Overflow in AMF
A buffer overflow vulnerability exists in the AMF of open5gs 2.1.4. When the length of MSIN in Supi exceeds 24 characters, it leads to AMF denial of service.
CVSS 7.5
CVE-2021-28122 WRITEUP CRITICAL
Open5GS 2.1.3-2.2.0 - Unauthenticated Database Manipulation via WebUI API
A request-validation issue was discovered in Open5GS 2.1.3 through 2.2.x before 2.2.1. The WebUI component allows an unauthenticated user to use a crafted HTTP API request to create, read, update, or delete entries in the subscriber database. For example, new administrative users can be added. The issue occurs because Express is not set up to require authentication.
CVSS 9.8
CVE-2021-28122 WRITEUP CRITICAL
Open5GS 2.1.3-2.2.0 - Unauthenticated Database Manipulation via WebUI API
A request-validation issue was discovered in Open5GS 2.1.3 through 2.2.x before 2.2.1. The WebUI component allows an unauthenticated user to use a crafted HTTP API request to create, read, update, or delete entries in the subscriber database. For example, new administrative users can be added. The issue occurs because Express is not set up to require authentication.
CVSS 9.8
CVE-2021-28122 WRITEUP CRITICAL
Open5GS 2.1.3-2.2.0 - Unauthenticated Database Manipulation via WebUI API
A request-validation issue was discovered in Open5GS 2.1.3 through 2.2.x before 2.2.1. The WebUI component allows an unauthenticated user to use a crafted HTTP API request to create, read, update, or delete entries in the subscriber database. For example, new administrative users can be added. The issue occurs because Express is not set up to require authentication.
CVSS 9.8
CVE-2021-28122 WRITEUP CRITICAL
Open5GS 2.1.3-2.2.0 - Unauthenticated Database Manipulation via WebUI API
A request-validation issue was discovered in Open5GS 2.1.3 through 2.2.x before 2.2.1. The WebUI component allows an unauthenticated user to use a crafted HTTP API request to create, read, update, or delete entries in the subscriber database. For example, new administrative users can be added. The issue occurs because Express is not set up to require authentication.
CVSS 9.8
CVE-2021-25863 WRITEUP HIGH
Open5GS 2.1.3 - Improper Authentication via Default Admin Credentials
Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account.
CVSS 8.8
CVE-2026-1587 WRITEUP MEDIUM
open5gs < 2.7.6 - Denial of Service in SGWC S11 Handler
A vulnerability has been found in Open5GS up to 2.7.6. The affected element is the function sgwc_s11_handle_modify_bearer_request of the file /sgwc/s11-handler.c of the component SGWC. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Applying a patch is the recommended action to fix this issue. The issue report is flagged as already-fixed.
CVSS 5.3
CVE-2026-1586 WRITEUP MEDIUM
open5gs < 2.7.6 - Denial of Service in SGWC S11 Handler
A flaw has been found in Open5GS up to 2.7.5. Impacted is the function ogs_gtp2_f_teid_to_ip of the file /sgwc/s11-handler.c of the component SGWC. Executing a manipulation can lead to denial of service. The attack may be performed from remote. The exploit has been published and may be used. It is advisable to implement a patch to correct this issue. The issue report is flagged as already-fixed.
CVSS 5.3
CVE-2026-1522 WRITEUP MEDIUM
open5gs < 2.7.6 - Denial of Service in SGWC S5C Handler
A weakness has been identified in Open5GS up to 2.7.6. This vulnerability affects the function sgwc_s5c_handle_modify_bearer_response of the file src/sgwc/s5c-handler.c of the component SGWC. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. This patch is called b19cf6a. Applying a patch is advised to resolve this issue. The issue report is flagged as already-fixed.
CVSS 5.3
CVE-2026-1521 WRITEUP MEDIUM
open5gs < 2.7.6 - Denial of Service in SGWC Bearer Resource Failure Indication Handler
A security flaw has been discovered in Open5GS up to 2.7.6. This affects the function sgwc_s5c_handle_bearer_resource_failure_indication of the file src/sgwc/s5c-handler.c of the component SGWC. Performing a manipulation results in denial of service. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The patch is named 69b53add90a9479d7960b822fc60601d659c328b. It is recommended to apply a patch to fix this issue.
CVSS 5.3
CVE-2025-15539 WRITEUP MEDIUM
open5gs < 2.7.6 - Denial of Service in sgwc_s11_handle_downlink_data_notification_ack
A vulnerability was determined in Open5GS up to 2.7.6. Impacted is the function sgwc_s11_handle_downlink_data_notification_ack of the file src/sgwc/s11-handler.c of the component sgwc. This manipulation causes denial of service. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Patch name: b4707272c1caf6a7d4dca905694ea55557a0545f. To fix this issue, it is recommended to deploy a patch. The issue report is flagged as already-fixed.
CVSS 5.3
CVE-2025-15532 WRITEUP MEDIUM
Open5GS < 2.7.5 - Denial of Service in Timer Handler
A security flaw has been discovered in Open5GS up to 2.7.5. This issue affects some unknown processing of the component Timer Handler. The manipulation results in resource consumption. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The patch is identified as c7c131f8d2cb1195ada5e0e691b6868ebcd8a845. It is best practice to apply a patch to resolve this issue.
CVSS 5.3
CVE-2025-15531 WRITEUP MEDIUM
open5gs < 2.7.5 - Reachable Assertion in sgwc_bearer_add Function
A vulnerability was identified in Open5GS up to 2.7.5. This vulnerability affects the function sgwc_bearer_add of the file src/sgwc/context.c. The manipulation leads to reachable assertion. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The issue report is flagged as already-fixed.
CVSS 5.3
CVE-2025-15530 WRITEUP MEDIUM
open5gs < 2.7.6 - Reachable Assertion in sgwc_s11_handle_create_indirect_data_forwarding_tunnel_request
A vulnerability was determined in Open5GS up to 2.7.6. This affects the function sgwc_s11_handle_create_indirect_data_forwarding_tunnel_request of the file /src/sgwc/s11-handler.c. Executing a manipulation can lead to reachable assertion. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The issue report is flagged as already-fixed.
CVSS 5.3
CVE-2025-15529 WRITEUP MEDIUM
Open5GS < 2.7.6 - Denial of Service in sgwc_s5c_handle_create_session_response
A vulnerability was found in Open5GS up to 2.7.6. Affected by this issue is the function sgwc_s5c_handle_create_session_response of the file src/sgwc/s5c-handler.c. Performing a manipulation results in denial of service. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The patch is named b19cf6a2dbf5d30811be4488bf059c865bd7d1d2. To fix this issue, it is recommended to deploy a patch.
CVSS 5.3
CVE-2025-15528 WRITEUP MEDIUM
Open5GS < 2.7.6 - Denial of Service in GTPv2 Bearer Response Handler
A vulnerability has been found in Open5GS up to 2.7.6. Affected by this vulnerability is an unknown functionality of the component GTPv2 Bearer Response Handler. Such manipulation leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The name of the patch is 98f76e98df35cd6a35e868aa62715db7f8141ac1. A patch should be applied to remediate this issue.
CVSS 5.3
CVE-2025-15419 WRITEUP LOW
open5gs < 2.7.6 - Denial of Service in GTPv2-C Flow Handler
A weakness has been identified in Open5GS up to 2.7.6. Affected by this issue is the function sgwc_s5c_handle_create_session_response of the file src/sgwc/s5c-handler.c of the component GTPv2-C Flow Handler. Executing a manipulation can lead to denial of service. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. This patch is called 5aaa09907e7b9e0a326265a5f08d56f54280b5f2. It is advisable to implement a patch to correct this issue.
CVSS 3.3