CVE-2025-63288: OPEN5GS

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In Open5GS 2.7.6, AMF crashes when receiving an abnormal NGSetupRequest message, resulting in denial of service.

Affected products

  • OPEN5GS OPEN5GS: version 2.7.6 only

Published 2025-11-10. Last modified 2026-06-17.