CVE-2026-25658

CVE-2026-25658

Improper Handling of Missing Values in Ericsson Packet Core Gateway (PCG) Versions Prior to 1.30

Improper Handling of Missing Values in Ericsson Packet Core Gateway (PCG) Versions Prior to 1.30

CVE ID
CVE-2026-25658
CVE Link
https://nvd.nist.gov/vuln/detail/CVE-2026-25658
Vendor
Ericsson
Affected Product & Version
Ericsson Packet Core Gateway (PCG) < 1.30
Vulnerability Type
CWE-228 - Improper Handling of Syntactically Invalid Structure
CVSS Base Score / CVSS Vector

NVD: 6.5 Medium  / CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Ericsson: 7.1 High / CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

BDO: 6.5 Medium  / CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Author
Clemens Keil, Manfred Heinz, Patrick Walker
Date
2026-06-05

CVE Details

Description:

Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structure (CWE-228) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.

Remediation:

Update PCG to the most recent version.

References:


Timeline

2025-11-05: Vulnerability discovered

2025-11-05: Vulnerability reported to Ericsson

2026-06-05: CVE published