CVE-2025-41068
Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause a denial of service. This is achieved by sending the creation of an NF with an invalid type via SBI and then requesting its data. The NRF executes a check that crashes the process, leaving the discovery service unresponsive.
- Affected products
- Open5Gs
- open5gs
- < 2.7.5
- Fix
- Available
- CVSS 4.0
- 8.7 HIGH
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.3% (26th percentile)
- Weakness
- CWE-617
- NVD status
- Modified
- Published
- 2025-10-27
Fix
The vulnerabilitiy has been fixed by the Open5GS team in version v2.7.6.
CVE-2025-41068 at NVD
2 known exploits for CVE-2025-41068
Proof-of-concept code and exploit modules indexed by Sploitus