PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-15686 Open5GS CVE debrief

A vulnerability was found in Open5GS up to 2.7.6, affecting the HSS Service component. The issue is caused by manipulation of the Session-Id argument in the fd_msg_sess_get function, leading to a denial of service. The attack can be performed remotely. The exploit has been disclosed publicly and may be used. This vulnerability has a CVSS score of 2.1 and a severity of LOW. Defenders responsible for Open5GS deployments should assess their exposure and potential impact of a denial-of-service attack.

Vendor
Open5GS
Product
Open5GS
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-12
Original CVE updated
2026-09-29
Advisory published
2026-08-12
Advisory updated
2026-09-29

Who should care

Defenders responsible for Open5GS deployments, especially those with remote access enabled, should assess their exposure and potential impact of a denial-of-service attack. IT teams and security personnel managing Open5GS installations should prioritize verifying exposure and implementing compensating controls to mitigate the risk.

Why it matters

CVE-2025-15686 is a denial-of-service vulnerability in Open5GS up to 2.7.6, affecting the HSS Service component. Defenders should prioritize verifying exposure, implementing compensating controls, and monitoring for suspicious activity to mitigate the risk of a denial-of-service attack.

  • Denial of service attacks can lead to service disruptions and impact business operations
  • Exposure to this vulnerability can allow attackers to perform remote denial-of-service attacks
  • Verification of Open5GS installations and implementation of compensating controls are necessary to mitigate the risk
  • Remediation priority is moderate, as the attack requires remote access and exploitation details are publicly available

Technical summary

The vulnerability affects Open5GS up to 2.7.6 and is caused by manipulation of the Session-Id argument in the fd_msg_sess_get function of the HSS Service component. This leads to a denial of service, which can be performed remotely. The exploit has been disclosed publicly and may be used. The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. However, further verification is required to establish versions beyond 2.7.6, exploitation, impact, or remediation.

Defensive priority

Defenders should prioritize verifying exposure of Open5GS installations, especially those with remote access enabled, and assess the potential impact of a denial-of-service attack.

Recommended defensive actions

  • Verify Open5GS installations for exposure, especially those with remote access enabled
  • Assess the potential impact of a denial-of-service attack on Open5GS deployments
  • Monitor Open5GS logs for suspicious activity related to the HSS Service component
  • Consider implementing compensating controls to mitigate the risk of a denial-of-service attack
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected versions. However, the corpus does not establish versions beyond 2.7.6, exploitation, impact, or remediation, which require verification from official sources.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-15686 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-15686

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-15686 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15686

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.