CVE-2025-63288: High severity open5gs open5gs vulnerability
Published Nov 10, 2025
·Updated
In Open5GS 2.7.6, AMF crashes when receiving an abnormal NGSetupRequest message, resulting in denial of service.
Affected Software
2 affected components
open5gs open5gs
open5gs open5gs=2.7.6
Remediation
Patch Available
Event History
Nov 10, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-63288?
CVE-2025-63288 is classified as a denial of service vulnerability due to the crashing of the AMF component.
2
How do I fix CVE-2025-63288?
To mitigate CVE-2025-63288, upgrade to the latest version of Open5GS that addresses this vulnerability.
3
Which versions of Open5GS are affected by CVE-2025-63288?
Open5GS versions prior to 2.7.6 are affected by CVE-2025-63288.
4
What causes the crash in CVE-2025-63288?
The crash in CVE-2025-63288 is triggered by receiving an abnormal NGSetupRequest message.
5
Is there a workaround for CVE-2025-63288?
Currently, the best approach to handle CVE-2025-63288 is to upgrade to a patched version of Open5GS.