CVE-2026-25657

Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structure (CWE-228) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ericsson:packet_core_gateway:*:*:*:*:*:*:*:*

History

08 Jun 2026, 14:21

Type Values Removed Values Added
References () https://www.ericsson.com/en/about-us/security/psirt/cve-2026-25657 - () https://www.ericsson.com/en/about-us/security/psirt/cve-2026-25657 - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Ericsson
Ericsson packet Core Gateway
CPE cpe:2.3:a:ericsson:packet_core_gateway:*:*:*:*:*:*:*:*

05 Jun 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-05 12:16

Updated : 2026-06-08 14:21


NVD link : CVE-2026-25657

Mitre link : CVE-2026-25657

CVE.ORG link : CVE-2026-25657


JSON object : View

Products Affected

ericsson

  • packet_core_gateway
CWE
CWE-228

Improper Handling of Syntactically Invalid Structure