CVE-2026-25657 PUBLISHED

Ericsson Packet Core Gateway (PCG) - Improper Handling of Syntactically Invalid Structure Vulnerability

Assigner: ERIC
Reserved: 04.02.2026 Published: 05.06.2026 Updated: 05.06.2026

Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structure (CWE-228) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor Ericsson
Product Packet Core Gateway (PCG)
Versions Default: affected
  • affected from 0 to 1.30 (excl.)

Credits

  • Clemens Keil, Manfred Heinz, Patrick Walker of BDO Cyber Security GmbH finder
  • BSI 5G/6G Security Lab TEMIS (Federal Office for Information Security, Germany) finder

References

Problem Types

  • CWE-228 CWE