216.73.216.36

CVE-2026-25658

· Published 05/06/2026 12:16 · Modified 05/06/2026 15:56

Labels: CVE-2026-25658 2026-06-0585b1779b-6ecd-4f52-bcc5-73eac4659dcfCVE-2026-25658CWE-230

Essential information

Published
05/06/2026 12:16
Modified
05/06/2026 15:56
Author
Creator
CVSS
7.1 HIGH (v3) 7.1 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.

NVD status

Status
Undergoing Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
85b1779b-6ecd-4f52-bcc5-73eac4659dcf
NVD
View on NVD

Affected products (CPE)

ProductCPE
ericsson / packet core gateway cpe:2.3:a:ericsson:packet_core_gateway:*:*:*:*:*:*:*:*

References