CVE-2025-25774: Medium severity open5gs open5gs vulnerability
An issue was discovered in Open5GS v2.7.2. When a UE switches between two gNBs and sends a handover request at a specific time, it may cause an exception in the AMF's internal state machine, leading to an AMF crash and resulting in a Denial of Service (DoS).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25774?
CVE-2025-25774 has a high severity rating due to its potential to cause Denial of Service (DoS) by crashing the AMF.
How do I fix CVE-2025-25774?
To address CVE-2025-25774, upgrade Open5GS to the latest version where the vulnerability has been patched.
What systems are affected by CVE-2025-25774?
CVE-2025-25774 specifically affects Open5GS version 2.7.2.
What can happen if CVE-2025-25774 is exploited?
Exploitation of CVE-2025-25774 can lead to an exception in the AMF's internal state machine and a subsequent crash, causing service disruption.
When does CVE-2025-25774 occur during operation?
CVE-2025-25774 occurs when a User Equipment (UE) switches between two gNBs and sends a handover request at a specific time.