Hardcoded Credential Vulnerability in Ericsson Packet Core Controller
CVE-2025-59180

5.1MEDIUM

Key Information:

Vendor

Ericsson

Vendor
CVE Published:
27 July 2026

What is CVE-2025-59180?

A vulnerability exists in Ericsson's Packet Core Controller where hardcoded credentials in the alarm system could allow an unauthorized attacker, who has access to the cluster and knowledge of these credentials, to access sensitive alarm and alert information. This flaw poses a significant risk as it may enable attackers to exploit alarm data for malicious activities or unauthorized monitoring.

Affected Version(s)

Packet Core Controller (PCC) 0 < 1.38

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Spark NZ
Radu Balaci and Meghna Patel from Bell Mobility (Canada)
.