CVE-2025-29646
HIGHopen5gs < 2.7.2 - Denial of Service via Crafted PFCP SessionEstablishmentRequest Packet
Title source: llmDescription
An issue in upf in open5gs 2.7.2 and earlier allows a remote attacker to cause a Denial of Service via a crafted PFCP SessionEstablishmentRequest packet with restoration indication = true and (teid = 0 or teid >= ogs_pfcp_pdr_teid_pool.size).
References (2)
Core 2
Core References
Exploit, Third Party Advisory
https://gist.github.com/scmdcs/581fa485f957239ea5551daa173d0189
Exploit, Issue Tracking
https://github.com/open5gs/open5gs/issues/3747
Scores
CVSS v3
7.1
EPSS
0.0023
EPSS Percentile
46.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-20
Status
published
Products (1)
open5gs/open5gs
< 2.7.2
Published
Jun 18, 2025
Tracked Since
Feb 18, 2026