CVE-2025-15555
Severity CVSS v4.0:
MEDIUM
Type:
CWE-119
Buffer Errors
Publication date:
04/02/2026
Last modified:
04/02/2026
Description
A security flaw has been discovered in Open5GS up to 2.7.6. Affected by this vulnerability is the function hss_ogs_diam_cx_mar_cb of the file src/hss/hss-cx-path.c of the component VoLTE Cx-Test. The manipulation of the argument OGS_KEY_LEN results in stack-based buffer overflow. The attack may be launched remotely. The patch is identified as 54dda041211098730221d0ae20a2f9f9173e7a21. A patch should be applied to remediate this issue.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
7.30
Severity 3.x
HIGH
Base Score 2.0
7.50
Severity 2.0
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/open5gs/open5gs/
- https://github.com/open5gs/open5gs/commit/54dda041211098730221d0ae20a2f9f9173e7a21
- https://github.com/open5gs/open5gs/issues/4177
- https://github.com/open5gs/open5gs/issues/4177#event-21256395700
- https://vuldb.com/?ctiid_343795=
- https://vuldb.com/?id_343795=
- https://vuldb.com/?submit_741901=



