Junglewise Threat Intelligence

CVE-2025-59172: Ericsson Packet Core Controller OS command injection

CVE-2025-59172 · Severity: info · CVSS 8.5 · Published 2026-07-27

Technologies: Ericsson Packet Core Controller. Vendors: Ericsson.

Executive brief

The Ericsson Packet Core Controller, a critical component used in mobile telecommunications networks to manage data traffic, contains a security vulnerability in versions prior to 1.38. An attacker with high-level administrative access could exploit this flaw to take full control of the system with root privileges. This could lead to a complete disruption of mobile services, unauthorized access to network traffic, or a total compromise of the controller's operations.

Technical details

An OS command injection vulnerability (CWE-78) exists in Ericsson Packet Core Controller (PCC) due to improper neutralization of special elements. The flaw allows an authenticated attacker with high privileges (PR:H) to execute arbitrary commands with root-level permissions on the underlying operating system. The attack vector is restricted to the adjacent network (AV:A), typically requiring access to the management network. The vulnerability is resolved in PCC version 1.38.

Affected products

  • Ericsson Packet Core Controller (PCC) versions prior to 1.38

Timeline

  • 2026-07-27: advisory: NVD and Ericsson published the advisory.
  • 1.38: patched: Vulnerability fixed in version 1.38.

References

Related threats