CVE-2026-33282 impacts Ella Core versions prior to 1.6.0, a 5G core solution for private networks. An unauthenticated attacker can trigger a denial of service by sending a malformed NGAP LocationReport message that causes the core process to panic. This vulnerability carries a CVSS score of 7.5 (High) due to its network-based attack vector and significant availability impact, disrupting service for all connected subscribers. There is no evidence of active exploitation, nor is public exploit code available, and community discussion remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.0CPE matchmatch criteria | cpe:2.3:a:ellanetworks:ella_core:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.