Denial of Service Vulnerability in Open5GS Products by Open5GS
CVE-2026-7518
Key Information:
Badges
What is CVE-2026-7518?
A vulnerability exists in Open5GS versions up to 2.7.7, where the function amf_namf_callback_handle_sdm_data_change_notify in the AMF SBI Endpoint allows an attacker to manipulate the argument changeItem.newValue, potentially leading to a denial of service. This vulnerability can be exploited remotely, allowing for significant disruption. The Open5GS team was notified of this issue; however, no resolution has been provided as of yet. The exploit details have been disclosed publicly, indicating the urgency for users to assess their risk and implement appropriate security measures.
Affected Version(s)
Open5GS 2.7.0
Open5GS 2.7.1
Open5GS 2.7.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
