CVE-2025-25774
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Mar 12, 2025
CWE ID 691
Summary
CVE-2025-25774 is a Denial of Service vulnerability affecting Open5GS version 2.7.2. When a User Equipment (UE) sends a handover request to switch between two gNBs during a specific time, an exception occurs within the AMF's internal state machine, causing the AMF to crash and become unavailable for legitimate traffic. This issue could potentially be exploited by an attacker to disrupt communication between network components, resulting in a significant service disruption.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Open5GS
Affected Vendors
- Open5gs