CVE-2026-25657
Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structure (CWE-228) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.17%
- CWE
- CWE-228
- Published
- 2026-06-05
- Last modified
- 2026-06-05
Affected products
- Ericsson Packet Core Gateway (PCG)
Weakness type
Related vulnerabilities
- CVE-2026-50103 — Improper Handling of Syntactically Invalid Structure in MZ Automation libIEC61850
- CVE-2025-59174 — Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an...
- CVE-2026-42100 — DoS in Sparx Pro Cloud Server
- CVE-2026-34232 — Firebird: DoS via `op_response` packet from client
- CVE-2024-53828 — Ericsson Packet Core Controller (PCC) - Improper Handling of Syntactically Invalid Structure Vulnerability
- CVE-2026-20125 — A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release...
- CVE-2025-2529 — IBM Terracotta denial of service
- CVE-2025-47736 — dialect/mod.rs in the libsql-sqlite3-parser crate through 0.13.0 before 14f422a for Rust can crash...