Denial of Service Vulnerability in Open5GS by Open5GS
CVE-2025-8803

6.9MEDIUM

Key Information:

Vendor

Open5GS

Status
Vendor
CVE Published:
10 August 2025

What is CVE-2025-8803?

A remote denial of service vulnerability has been identified in the Open5GS Access and Mobility Management Function (AMF), specifically in the gmm_state_de_registered and gmm_state_exception functions. This flaw allows attackers to disrupt service and affect application performance. The issue has been addressed in version 2.7.6, and users are strongly encouraged to upgrade their installations to avoid potential service interruptions. The corresponding patch can be found in commit 1f30edac27f69f61cff50162e980fe58fdeb30ca.

Affected Version(s)

Open5GS 2.7.0

Open5GS 2.7.1

Open5GS 2.7.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

xiaohan zheng (VulDB User)
.
CVE-2025-8803 : Denial of Service Vulnerability in Open5GS by Open5GS