CVE-2026-25658
Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.17%
- CWE
- CWE-230
- Published
- 2026-06-05
- Last modified
- 2026-06-05
Affected products
- Ericsson Packet Core Gateway (PCG)
Weakness type
Related vulnerabilities
- CVE-2026-25659 — Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerability
- CVE-2026-20086 — A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP)...
- CVE-2026-1461 — Simple Membership <= 4.7.0 - Unauthenticated Improper Handling of Missing Values
- CVE-2025-23225 — IBM MQ denial of service
- CVE-2024-11024 — AppPresser – Mobile App Framework <= 4.4.6 - Unauthenticated Privilege Escalation via Password Reset
- CVE-2024-10508 — RegistrationMagic – User Registration Plugin with Custom Registration Forms <= 6.0.2.6 - Unauthenticated Privilege Escalation via Password Recovery
- CVE-2024-9781 — Improper Handling of Missing Values in Wireshark
- CVE-2024-6237 — 389-ds-base: unauthenticated user can trigger a dos by sending a specific extended search request