CVE-2025-15531

MEDIUM

Open5gs < 2.7.5 - Reachable Assertion

Title source: rule

Description

A vulnerability was identified in Open5GS up to 2.7.5. This vulnerability affects the function sgwc_bearer_add of the file src/sgwc/context.c. The manipulation leads to reachable assertion. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The issue report is flagged as already-fixed.

Scores

CVSS v3 5.3
EPSS 0.0012
EPSS Percentile 31.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Classification

CWE
CWE-617
Status published

Affected Products (1)

open5gs/open5gs < 2.7.5

Timeline

Published Jan 17, 2026
Tracked Since Feb 18, 2026