CVE-2025-15555 Details
Description
A security flaw has been discovered in Open5GS up to 2.7.6. Affected by this vulnerability is the function hss_ogs_diam_cx_mar_cb of the file src/hss/hss-cx-path.c of the component VoLTE Cx-Test. The manipulation of the argument OGS_KEY_LEN results in stack-based buffer overflow. The attack may be launched remotely. The patch is identified as 54dda041211098730221d0ae20a2f9f9173e7a21. A patch should be applied to remediate this issue.
A stack-based buffer over-read vulnerability has been identified in Open5GS versions through 2.7.6. The issue arises in the VoLTE Cx-Test component, specifically within the 'hss_ogs_diam_cx_mar_cb' function of 'src/hss/hss-cx-path.c'. The vulnerability is caused by logging the 'ak' buffer using 'OGS_KEY_LEN', while the buffer is allocated with 'OGS_AK_LEN'. This mismatch leads to a stack buffer over-read during logging, which could cause instability or information leakage. The vulnerability can be exploited remotely.
Users are advised to update to the patched version of Open5GS. The patch is available in the official Open5GS GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/open5gs/open5gs/issues/4177#event-21256395700 | CISA-ADP | ExploitIssue TrackingThird Party Advisory |
| https://github.com/open5gs/open5gs/ | [email protected] | Product |
| https://github.com/open5gs/open5gs/commit/54dda041211098730221d0ae20a2f9f9173e7a21 | [email protected] | Patch |
| https://github.com/open5gs/open5gs/issues/4177 | [email protected] | ExploitIssue TrackingThird Party Advisory |
| https://github.com/open5gs/open5gs/issues/4177#event-21256395700 | [email protected] | ExploitIssue TrackingThird Party Advisory |
| https://vuldb.com/submit/741901 | [email protected] | |
| https://vuldb.com/vuln/343795 | [email protected] | |
| https://vuldb.com/vuln/343795/cti | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| open5gs open5gs | <= 2.7.6 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 7, 2026 | CVE Modified | [email protected] |
| Feb 11, 2026 | Initial Analysis | [email protected] |
| Feb 5, 2026 | CVE Modified | CISA-ADP |
| Feb 4, 2026 | New CVE Received | [email protected] |