# CVE-2025-15685

## Summary

- **CVE ID:** CVE-2025-15685
- **Severity:** MEDIUM
- **CVSS Score:** 6.5 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X)
- **CWE:** CWE-119
- **Published:** Aug 12, 2026
- **Last Modified:** Aug 12, 2026

## Description

A flaw has been found in Open5GS up to 2.7.1. Affected by this vulnerability is an unknown functionality of the component freeDiameter. This manipulation causes memory corruption. The attack is possible to be carried out remotely.

## Affected Products

- n/a — Open5GS (2.7.0)
- n/a — Open5GS (2.7.1)

## References

- [CNA](https://vuldb.com/vuln/387278)
- [CNA](https://vuldb.com/vuln/387278/cti)
- [CNA](https://vuldb.com/cve/CVE-2025-15685)
- [CNA](https://vuldb.com/submit/867103)
- [CNA](https://github.com/open5gs/open5gs/issues/4156)
- [CNA](https://github.com/open5gs/open5gs/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.23%
- **EPSS Percentile:** 13.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._