Null Pointer Dereference Vulnerability in OMEC Project UPF by Aether SD-Core
CVE-2025-15156
Key Information:
- Vendor
Omec-project
- Status
- Vendor
- CVE Published:
- 28 December 2025
Badges
What is CVE-2025-15156?
A vulnerability has been identified in OMEC Project UPF that impacts versions up to 2.1.3-dev. The flaw exists within the handleSessionEstablishmentRequest function of the /pfcpiface/pfcpiface/messages_session.go file, where a null pointer dereference occurs. This issue can potentially be exploited remotely, allowing attackers to manipulate session establishment requests. Despite earlier notification of the issue through an issue report, the project stakeholders have not yet addressed it.
Affected Version(s)
UPF 2.1.3-dev
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
