CVE-2025-48219 Details
Description
O2 UK before 2025-05-19 allows subscribers to determine the Cell ID of other subscribers by initiating an IMS (IP Multimedia Subsystem) call and then reading the utran-cell-id-3gpp field of a Cellular-Network-Info SIP header, aka an ECI (E-UTRAN Cell Identity) leak. The Cell ID might be usable to identify a cell location via crowdsourced data, and might correspond to a small physical area (e.g., if the called party is in a city centre). Removal of the Cellular-Network-Info header is mentioned in section 4.4.19 of ETSI TS 124 229.
A vulnerability in O2 UK's Voice over LTE (VoLTE) service has been identified, allowing subscribers to unintentionally disclose the E-UTRAN Cell Identity (ECI) of other users. This issue arises when an IMS (IP Multimedia Subsystem) call is made, as the 'Cellular-Network-Info' SIP header includes the utran-cell-id-3gpp field, which reveals the Cell ID. This information could be used to approximate a user's location, particularly in urban areas where cell coverage is dense. The vulnerability affects all O2 UK customers using VoLTE or WiFi Calling.
O2 UK has confirmed that the issue has been fixed. Customers do not need to take any action.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 18, 2025CISA-ADP
Assessed May 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://mastdatabase.co.uk/blog/2025/05/o2-expose-customer-location-call-4g/ | [email protected] | ExploitMedia CoverageRemedyTechnical Analysis |
| https://news.ycombinator.com/item?id=44014046 | [email protected] | Media CoverageTechnical Description |
| https://www.etsi.org/deliver/etsi_ts/124200_124299/124229/15.10.00_60/ts_124229v151000p.pdf | [email protected] | Not Applicable |
| https://www.ispreview.co.uk/index.php/2025/05/o2-uk-fixes-volte-flaw-that-exposed-user-mobile-location-data.html | [email protected] | AdvisoryMedia CoverageRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-201 | Insertion of Sensitive Information Into Sent Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| O2 UK | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 19, 2025 | CVE Modified | [email protected] |
| May 18, 2025 | New CVE Received | [email protected] |
Volerion