Executive brief
Open5GS is an open-source implementation of a 5G core network and LTE/EPC. A vulnerability in the AMF (Access and Mobility Management Function) and MME (Mobility Management Entity) components allows attackers to bypass authorization checks remotely. This could enable unauthorized network access or manipulation of user equipment contexts in mobile networks.
Technical details
An improper authorization vulnerability exists in Open5GS versions 2.7.7 and 2.8.0 within the AMF and MME components. The vulnerability arises from insufficient validation of UE (User Equipment) associations during partial NG RESET and S1 RESET operations. An attacker can remotely exploit this by sending specially crafted reset messages that are not properly authenticated, allowing them to manipulate UE context associations or access resources without proper authorization. The fix involves validating that UE contexts referenced in reset operations belong to the requesting gNB/eNB and that core-network and RAN identifiers refer to the same UE association. A patch has been released and is available at commit 9468de94caed2fc940f4a23cbf734651896d0fde.
Affected products
- Open5GS Open5GS 2.7.7, 2.8.0
Timeline
- 2026-09-06: disclosed
- 2026-09-06: patched: Patch available at commit 9468de94caed2fc940f4a23cbf734651896d0fde