Junglewise Threat Intelligence

CVE-2026-25659: Ericsson Packet Core Gateway denial of service via improper handling of missing values

CVE-2026-25659 · Severity: info · CVSS 7.1 · Published 2026-06-05

Technologies: Ericsson Packet Core Gateway. Vendors: Ericsson.

Executive brief

The Ericsson Packet Core Gateway, a critical component for managing mobile network traffic, is susceptible to a denial-of-service attack. An attacker can send specifically formatted messages that cause the system to crash or degrade in performance, potentially disrupting mobile data services for users. While the system recovers once the attack stops, the vulnerability can be used to cause ongoing operational instability.

Technical details

The vulnerability is classified as Improper Handling of Missing Values (CWE-230) within the Ericsson Packet Core Gateway (PCG). It is triggered when the gateway receives specially crafted messages that lack expected values, leading to service instability or crashes. The attack vector is defined as 'Adjacent,' meaning the attacker must be on the same local network or subnet as the gateway. Exploitation results in a denial-of-service (DoS) condition that persists as long as the malicious traffic is being sent; the system reportedly recovers automatically once the attack ceases. This issue is resolved in PCG version 1.30.

Affected products

  • Ericsson Packet Core Gateway (PCG) prior to 1.30

Timeline

  • 2026-06-05: advisory: Initial disclosure by Ericsson and NVD publication.

References

Related threats