CVE-2025-41067
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
27/10/2025
Last modified:
29/10/2025
Description
Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause a denial of service. An SBI request that deletes the NRF's own registry causes a check that ends up crashing the NRF process and renders the discovery service unavailable.
Impact
Base Score 4.0
8.70
Severity 4.0
HIGH
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:* | 2.7.5 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



