Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Openairinterface

First CVE: Mar 27, 2025Active for: 1 yearTotal CVEs: 9

OpenAirInterface is a narrowly scoped telecommunications software project centered on 5G network components, particularly its core network and radio access implementations, that despite limited product breadth occupies a specialist role in emerging cellular infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes and recur through weakness classes including improper input validation, authentication bypass mechanisms, and buffer-overflow conditions that reflect the protocol-handling and access-control demands of network infrastructure code. Defenders deploying or testing this vendor's 5G implementations should treat authentication and input-handling issues as high-priority; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Openairinterface over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 27, 2025
15 months ago
Most Recent CVE
Jun 1, 2026
53 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-37232HIGH
An issue was discovered in OpenAirInterface5G 2.4.0 (nr-softmodem) in the E2SM-KPM RAN Function's PRB utilization metric calculation. The functions fill_RRU_PrbTotDl() and fill_RRU
Jun 1, 20268.634NONO
CVE-2026-30079CRITICAL
In OpenAirInterface V2.2.0 AMF, Out of sequence messages causes incorrect state transition during UE registration procedure. This allows authentication to be bypassed completely. I
Apr 7, 20269.830NONO
CVE-2026-30078HIGH
OpenAirInterface V2.2.0 AMF crashes when it receives an NGAP message with invalid procedure code or invalid PDU-type. For example when the message specification requires Initiating
Apr 6, 20267.527NONO
CVE-2026-30080HIGH
OpenAirInterface v2.2.0 accepts Security Mode Complete without any integrity protection. Configuration has supported integrity NIA1 and NIA2. But if an UE sends initial registratio
Apr 8, 20267.525NONO
CVE-2026-30075HIGH
OpenAirInterface Version 2.2.0 has a Buffer Overflow vulnerability in processing UplinkNASTransport containing Authentication Response containing a NAS PDU with oversize response (
Apr 8, 20267.525NONO
CVE-2026-30077HIGH
OpenAirInterface V2.2.0 AMF crashes when it fails to decode the message. Not all decode failures result in a crash. But the crash is consistent for particular inputs. An example in
Mar 30, 20267.524NONO
CVE-2025-66786HIGH
OpenAirInterface CN5G AMF<=v2.0.1 There is a logical error when processing JSON format requests. Unauthorized remote attackers can send malicious JSON data to AMF's SBI interface t
Jan 7, 20267.524NONO
CVE-2025-65805HIGH
OpenAirInterface CN5G AMF<=v2.1.9 has a buffer overflow vulnerability in processing NAS messages. Unauthorized remote attackers can launch a denial-of-service attack and potentiall
Jan 7, 20267.522NONO
CVE-2025-26265MEDIUM
A segmentation fault in openairinterface5g v2.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted UE Context Modification response.
Mar 27, 20256.520NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
11%
78%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (88.9%)
Unknown0 (0.0%)
Required1 (11.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None9 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Openairinterface.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Openairinterface — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Openairinterface's Products

View all 1 CNAs →

Top CWEs