CVE-2025-52322: OPEN5GS

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue in Open5GS v2.7.2 and before allows a remote attacker to cause a denial of service via a crafted Create Session Request message to the SMF (PGW-C), using the IP address of a legitimate UE in the PDN Address Allocation (PAA) field

Affected products

  • OPEN5GS OPEN5GS: up to and including 2.7.2

Published 2025-09-09. Last modified 2026-06-17.