Junglewise Threat Intelligence

CVE-2026-37235: EURECOM FlexRIC xApp impersonation and DoS in iApp component

CVE-2026-37235 · Severity: info · CVSS 9.1 · Published 2026-06-01

Technologies: EURECOM FlexRIC. Vendors: EURECOM.

Executive brief

FlexRIC, a controller used in Open RAN cellular networks to manage radio functions, contains a vulnerability that allows an attacker to impersonate legitimate applications (xApps). By sending specially crafted messages, an attacker can trick the controller into misrouting data or commands to the wrong application. This can lead to a complete crash of the controller or the connected applications, disrupting cellular network operations and service availability.

Technical details

FlexRIC v2.0.0 fails to cryptographically or logically bind the 'xapp_id' field in E42 message payloads to the sender's underlying SCTP association. The validation function 'valid_xapp_id()' in 'src/ric/iApp/msg_handler_iapp.c' only verifies that the ID is within a valid numeric range rather than verifying ownership. A remote unauthenticated attacker can send E42_RIC_SUBSCRIPTION_REQUEST messages to port 36422 using a victim's predictable xapp_id. This results in response misrouting and state inconsistencies within the red-black tree data structures, leading to Denial of Service (DoS) via crashes of the victim xApp, the near-RT RIC, or the iApp component.

Affected products

  • EURECOM FlexRIC v2.0.0 through commit 6a595d8b (2025-11-12)

Timeline

  • 2026-06-01: disclosed
  • 2026-06-01: advisory

References

Related threats