CVE-2025-25774: OPEN5GS

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue was discovered in Open5GS v2.7.2. When a UE switches between two gNBs and sends a handover request at a specific time, it may cause an exception in the AMF's internal state machine, leading to an AMF crash and resulting in a Denial of Service (DoS).

Affected products

  • OPEN5GS OPEN5GS: version 2.7.2 only

Published 2025-03-12. Last modified 2026-06-17.