CVE-2024-25008: Ericsson Controller 6610

Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Ericsson RAN Compute and Site Controller 6610 contains a vulnerability in the Control System where Improper Input Validation can lead to arbitrary code execution, for example to obtain a Linux Shell with the same privileges as the attacker. The attacker would require elevated privileges for example a valid OAM user having the system administrator role to exploit the vulnerability.

Affected products

  • Ericsson Controller 6610: before 24.q2 (fixed in 24.q2)
  • Ericsson Ericsson Ran Compute Basebands All Bb Variants: before 24.Q2 (fixed in 24.Q2)
  • Ericsson Ran Compute: before 24.q2 (fixed in 24.q2)
  • Ericsson Site Controller 6610: before 24.Q2 (fixed in 24.Q2)

Published 2024-08-16. Last modified 2026-06-17.