CVE-2025-6952 Details
Description
A vulnerability, which was classified as problematic, has been found in Open5GS up to 2.7.5. This issue affects the function amf_state_operational of the file src/amf/amf-sm.c of the component AMF Service. The manipulation leads to reachable assertion. It is possible to launch the attack on the local host. The identifier of the patch is 53e9e059ed96b940f7ddcd9a2b68cb512524d5db. It is recommended to apply a patch to fix this issue.
A denial-of-service vulnerability has been identified in Open5GS versions through 2.7.5, specifically within the AMF service. The issue arises in the 'amf_state_operational' function of 'src/amf/amf-sm.c', where an assertion failure can be triggered. This vulnerability is exploited by sending a SIGTERM signal to the AMF process during its initialization phase, after it has dispatched subscription requests to the NRF but before those responses are received. As a result, the internal state machine is left in an invalid state, causing the AMF process to crash. This exploitation leads to a disruption of 5G core network services, preventing gNodeBs and user equipment from establishing connections.
Users are advised to update to the patched version of Open5GS, which is available on the Open5GS GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/open5gs/open5gs/commit/53e9e059ed96b940f7ddcd9a2b68cb512524d5db | [email protected] | Patch |
| https://github.com/open5gs/open5gs/issues/3938 | [email protected] | ExploitIssue TrackingThird Party Advisory |
| https://github.com/open5gs/open5gs/issues/3938#issuecomment-3012139813 | [email protected] | Issue Tracking |
| https://vuldb.com/?ctiid.314489 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.314489 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.605312 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-617 | Reachable Assertion | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| open5gs open5gs | < 2.7.6 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 25, 2025 | Initial Analysis | [email protected] |
| Jul 1, 2025 | New CVE Received | [email protected] |