CVE-2025-15532 is a high-severity resource consumption vulnerability affecting Open5GS versions up to 2.7.5, specifically within an unknown processing component of the Timer Handler. This flaw, rated 7.5 CVSS, allows unauthenticated remote attackers to cause denial-of-service by consuming system resources. While not currently in CISA's KEV catalog, a public exploit exists, and it has garnered significant community discussion, indicating potential for future attacks. Organizations using affected Open5GS versions should apply the patch identified as c7c131f8d2cb1195ada5e0e691b6868ebcd8a845 immediately.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.7.5CPE matchmatch criteria | cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.