CVE-2026-25657

CVE-2026-25657

Improper Handling of Syntactically Invalid Structures in Ericsson Packet Core Gateway (PCG) prior to 1.30

Improper Handling of Syntactically Invalid Structures in Ericsson Packet Core Gateway (PCG) prior to 1.30

CVE ID
CVE-2026-25657
CVE Link
https://nvd.nist.gov/vuln/detail/CVE-2026-25657
Vendor
Ericsson
Affected Product & Version
Ericsson Packet Core Gateway (PCG) < 1.30
Vulnerability Type
CWE-228 - Improper Handling of Syntactically Invalid Structure
CVSS Base Score / CVSS Vector

NVD: 6.5 Medium  / CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Ericsson: 7.1 High / CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

BDO: 6.5 Medium  / CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Author
Clemens Keil, Manfred Heinz, Patrick Walker
Date
2026-06-05

CVE Details

Description:

Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structure (CWE-228) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.

Remediation:

Update PCG to the most recent version.

References:


Timeline

2025-11-05: Vulnerability discovered

2025-11-05: Vulnerability reported to Ericsson

2026-06-05: CVE published