PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-15684 Open5GS CVE debrief

A vulnerability was detected in Open5GS up to 2.7.6. The function diam_log_func of the file lib/diameter/common/init.c of the component CER Handler is affected, leading to a reachable assertion. The attack can be executed remotely. Upgrading to version 2.7.7 addresses this issue. The patch is identified as c1a803516a3c0485696cb9bcca7a80ad857c7383. Defenders should assess exposure and consider upgrading or applying the patch. The CVE record and NVD entry provide additional context on the vulnerability.

Vendor
Open5GS
Product
Open5GS
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-12
Original CVE updated
2026-09-29
Advisory published
2026-08-12
Advisory updated
2026-09-29

Who should care

Defenders responsible for Open5GS deployments should assess exposure and prioritize upgrading to version 2.7.7 or applying the patch c1a803516a3c0485696cb9bcca7a80ad857c7383. Security teams and vulnerability management teams should review the vulnerability details and plan for remediation. Open5GS operators and administrators should verify their deployments and consider the potential operational impacts of the vulnerability. IT and network security teams,

Why it matters

CVE-2025-15684 is a vulnerability in Open5GS that can be exploited remotely, leading to a reachable assertion. Defenders should prioritize upgrading to version 2.7.7 or applying the patch.

  • Verify and upgrade Open5GS to version 2.7.7 or later to prevent potential remote exploitation
  • Apply patch c1a803516a3c0485696cb9bcca7a80ad857c7383 to vulnerable systems
  • Review system configurations and update affected components

Technical summary

The diam_log_func function in lib/diameter/common/init.c of Open5GS up to 2.7.6 is vulnerable to a reachable assertion. This can be exploited remotely due to improper handling of CER requests. Upgrading to version 2.7.7 or applying the patch c1a803516a3c0485696cb9bcca7a80ad857c7383 mitigates the vulnerability. Defenders should focus on upgrading or patching affected systems to prevent potential remote exploitation. The vulnerability is in the CER Handler component, which is a critical part of the Open5GS system. The reachable assertion can lead to a denial of service or potentially more severe impacts.

Defensive priority

Defenders should prioritize upgrading Open5GS to version 2.7.7 or applying the patch c1a803516a3c0485696cb9bcca7a80ad857c7383 to mitigate the vulnerability.

Recommended defensive actions

  • Upgrade Open5GS to version 2.7.7 or later
  • Apply the patch c1a803516a3c0485696cb9bcca7a80ad857c7383
  • Review and update affected systems
  • Verify Open5GS deployments for exposure
  • Assess and prioritize upgrading or applying the patch
  • Monitor for potential exploitation attempts
  • Review system configurations and update affected components

Evidence notes

The CVE record and NVD entry provide details about the vulnerability in Open5GS. The vendor has released a patch (c1a803516a3c0485696cb9bcca7a80ad857c7383) and an updated version (2.7.7) to address the issue. Defenders should verify Open5GS deployments and consider upgrading or applying the patch. The vulnerability can be exploited remotely, leading to a reachable assertion.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-15684 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-15684

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-15684 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15684

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.