CVE-2025-15686
Received Received - Intake

Denial of Service in Open5GS HSS Service

Vulnerability report for CVE-2025-15686, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-12

Assigner: VulDB

Description

A vulnerability has been found in Open5GS up to 2.7.6. Affected by this issue is the function fd_msg_sess_get of the component HSS Service. Such manipulation of the argument Session-Id leads to denial of service. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The project locked and limited conversation to collaborators.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-12
Generated
2026-08-12
AI Q&A
2026-08-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
open5gs open5gs to 2.7.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-404 The product does not release or incorrectly releases a resource before it is made available for re-use.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2025-15686 is a denial-of-service vulnerability in Open5GS versions up to 2.7.6. It occurs in the Home Subscriber Server (HSS) component when processing a malformed Diameter protocol Update-Location-Request (ULR) message. The issue is triggered by sending a Capabilities-Exchange-Request (CER) followed by an erroneous ULR message with an invalid or missing Destination-Realm attribute. This causes a parsing error in the Diameter protocol handler, leading to an assertion failure in the freeDiameter library and a crash of the HSS service.

Detection Guidance

Monitor Open5GS HSS logs for Diameter protocol parsing errors or crashes. Check for malformed Update-Location-Request (ULR) messages with missing or incorrect Destination-Realm attributes. Use Wireshark to capture Diameter traffic and filter for malformed AVP (Attribute-Value Pair) errors in HSS interactions.

Impact Analysis

This vulnerability allows remote attackers to crash the HSS service by sending malformed network messages. The impact includes service disruption for the 5G core network, as the HSS is critical for subscriber management. Affected systems may experience unexpected downtime or require manual intervention to restore normal operation.

Mitigation Strategies

Upgrade Open5GS to a version beyond 2.7.6 where the Diameter protocol handler has been fixed. Apply patches from the Open5GS GitHub repository if available. Restrict network access to the HSS component to trusted Diameter peers only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-15686. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart