Improper Neutralization Vulnerability in Ericsson Packet Core Controller
CVE-2025-59172

8.5HIGH

Key Information:

Vendor

Ericsson

Vendor
CVE Published:
27 July 2026

What is CVE-2025-59172?

The Ericsson Packet Core Controller (PCC) has a vulnerability that allows attackers to execute arbitrary code with root privileges. This flaw, stemming from improper neutralization of special elements, affects versions prior to 1.38. Exploiting this vulnerability could lead to unauthorized access and manipulation of the system, emphasizing the need for immediate updates and patches.

Affected Version(s)

Packet Core Controller (PCC) 0 < 1.38

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Spark NZ
Radu Balaci and Meghna Patel from Bell Mobility (Canada)
.