CVE-2025-59172: Ericsson Packet Core Controller Pcc

High severity, CVSS 8.5. EPSS: 0.3% chance of exploitation in the next 30 days.

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root.

Affected products

  • Ericsson Packet Core Controller Pcc: before 1.38 (fixed in 1.38)

Published 2026-07-27. Last modified 2026-09-29.