Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structure (CWE-228) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.
References
| Link | Resource |
|---|---|
| https://www.ericsson.com/en/about-us/security/psirt/cve-2026-25657 | Vendor Advisory |
Configurations
History
08 Jun 2026, 14:21
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.ericsson.com/en/about-us/security/psirt/cve-2026-25657 - Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| First Time |
Ericsson
Ericsson packet Core Gateway |
|
| CPE | cpe:2.3:a:ericsson:packet_core_gateway:*:*:*:*:*:*:*:* |
05 Jun 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-05 12:16
Updated : 2026-06-08 14:21
NVD link : CVE-2026-25657
Mitre link : CVE-2026-25657
CVE.ORG link : CVE-2026-25657
JSON object : View
Products Affected
ericsson
- packet_core_gateway
CWE
CWE-228
Improper Handling of Syntactically Invalid Structure
