Junglewise Threat Intelligence

CVE-2025-15687: Open5GS denial of service in SMF Diameter Gx Credit-Control-Answer

CVE-2025-15687 · Severity: medium · CVSS 4.3 · Published 2026-08-12

Technologies: Open5GS. Vendors: Open5GS.

Executive brief

Open5GS is an open-source 5G core network implementation used to operate LTE and 5G networks. A flaw in the SMF (Session Management Function) component's handling of Diameter Gx Credit-Control-Answer messages can be exploited remotely to cause a denial of service, disrupting network service availability.

Technical details

The vulnerability exists in the smf_gx_cca_cb callback function of the SMF Diameter Gx Credit-Control-Answer handler in Open5GS up to version 2.7.6. The flaw involves improper exception handling that fails to gracefully process unexpected or late Diameter messages, leading to assertion failures and denial of service. An attacker can remotely trigger this condition without authentication by sending malformed or out-of-sequence Diameter Gx Credit-Control-Answer messages to the SMF component. The issue was fixed in version 2.7.7 with commit f23d7a5e, which added robust error checks and logging to prevent assertion failures.

Affected products

  • Open5GS Open5GS up to 2.7.6

Timeline

  • 2026-08-12: disclosed
  • 2026-08-12: patched: Version 2.7.7 and commit f23d7a5e

References

Related threats