CVE-2026-33907 affects Ella Core 5G core versions prior to 1.7.0, where a vulnerability exists in its handling of NAS messages. This medium-severity flaw (CVSS 6.5) allows an unauthenticated attacker on an adjacent network to cause a denial of service. By sending crafted Authentication Response or Failure NAS messages with missing Information Elements, the attacker can crash the Ella Core process, disrupting service for all connected subscribers. There are no known public exploits, Metasploit modules, or active exploitation reports for this vulnerability, which has seen minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.0CPE matchmatch criteria | cpe:2.3:a:ellanetworks:ella_core:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.