Open5GS是Open5GS开源的一个 5G Core 和 Epc 的 C 语言开源实现,即 Lte/Nr 网络的核心网络。 Open5GS 2.7.6及之前版本存在授权问题漏洞,该漏洞源于组件NGAP PathSwitchRequest Message Handler中文件src/amf/ngap-handler.c的未知函数导致身份验证不当,攻击者可远程发起攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Open5GS | 2.7.0 |
cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-10204 | 6.3 MEDIUM | OFCMS JSON Query SysUserController.java query sql injection |
| CVE-2026-10203 | 6.3 MEDIUM | OFCMS JSON Query SystemParamController.java query sql injection |
| CVE-2026-10202 | 6.3 MEDIUM | OFCMS JSON Query SystemDictController.java query sql injection |
| CVE-2026-10193 | 6.3 MEDIUM | OFCMS ComnController ComnController.java query sql injection |
| CVE-2026-10200 | 5.3 MEDIUM | Assimp 4x4 Matrix glTFCommon.h CopyValue heap-based overflow |
| CVE-2026-10201 | 3.3 LOW | Assimp UV Channel FBXExporter.cpp WriteObjects divide by zero |
| CVE-2026-10199 | 3.3 LOW | Assimp glTF2Asset.h LazyDict null pointer dereference |
| CVE-2026-10198 | 3.3 LOW | Assimp glTFImporter glTFImporter.cpp ImportMeshes null pointer dereference |
| CVE-2026-10197 | 3.3 LOW | Assimp TF File glTF2Importer.cpp ImportEmbeddedTextures null pointer dereference |
No comments yet