CVE-2025-15531
MEDIUMOpen5gs < 2.7.5 - Reachable Assertion
Title source: ruleDescription
A vulnerability was identified in Open5GS up to 2.7.5. This vulnerability affects the function sgwc_bearer_add of the file src/sgwc/context.c. The manipulation leads to reachable assertion. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The issue report is flagged as already-fixed.
References (6)
Scores
CVSS v3
5.3
EPSS
0.0012
EPSS Percentile
31.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Classification
CWE
CWE-617
Status
published
Affected Products (1)
open5gs/open5gs
< 2.7.5
Timeline
Published
Jan 17, 2026
Tracked Since
Feb 18, 2026