CVE-2026-25657: Ericsson Packet Core Gateway (PCG) - Improper Handling of Syntactically Invalid Structure Vulnerability
Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structure (CWE-228) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ericsson Packet Core Gateway (PCG)to a version that resolves this vulnerability.Fixed in 1.30
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25657?
CVE-2026-25657 has a severity rating of 7.1, classified as high.
What is CVE-2026-25657 about?
CVE-2026-25657 refers to an improper handling of syntactically invalid structure vulnerability in Ericsson Packet Core Gateway.
How can I fix CVE-2026-25657?
The best way to fix CVE-2026-25657 is to update to Ericsson Packet Core Gateway version 1.30 or later.
What impact does CVE-2026-25657 have?
CVE-2026-25657 allows an attacker to cause service degradation through continuous attacks using specially crafted messages.
Which versions are affected by CVE-2026-25657?
Ericsson Packet Core Gateway versions prior to 1.30 are affected by CVE-2026-25657.