Open5GS是Open5GS开源的一个 5G Core 和 Epc 的 C 语言开源实现,即 Lte/Nr 网络的核心网络。 Open5GS 2.7.7及之前版本存在安全漏洞,该漏洞源于组件NSSF中文件/src/nssf/nnssf-handler.c的函数nssf_nnrf_nsselection_handle_get_from_amf_or_vnssf操作导致拒绝服务,可能远程攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Open5GS | 2.7.0 |
cpe:2.3:a:open5gs:open5gs:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-8127 | 6.3 MEDIUM | eladmin Users API Endpoint UserController.java checkLevel access control |
| CVE-2026-8123 | 4.3 MEDIUM | Open5GS NSSF message.c ogs_sbi_discovery_option_add_snssais denial of service |
| CVE-2026-8122 | 4.3 MEDIUM | Open5GS NSSF message.c ogs_sbi_discovery_option_add_service_names denial of service |
| CVE-2026-8121 | 4.3 MEDIUM | Open5GS NSSF conv.c ogs_sbi_parse_plmn_list denial of service |
| CVE-2026-8124 | 3.3 LOW | GPAC box_code_base.c sidx_box_read allocation of resources |
| CVE-2026-8119 | 3.3 LOW | Open5GS NSSF nghttp2-server.c ogs_sbi_stream_find_by_id denial of service |
| CVE-2025-67888 | Control Web Panel 操作系统命令注入漏洞 | |
| CVE-2025-67887 | 1C-Bitrix 安全漏洞 | |
| CVE-2025-67886 | Bitrix24 代码问题漏洞 | |
| CVE-2025-69690 | pfSense 安全漏洞 | |
| CVE-2025-69691 | pfSense 安全漏洞 | |
| CVE-2025-69599 | RayVentory Scan Engine 安全漏洞 | |
| CVE-2025-55449 | AstrBot 安全漏洞 | |
| CVE-2023-46453 | GL.iNet Router 安全漏洞 | |
| CVE-2026-38361 | dash-uploader 资源管理错误漏洞 | |
| CVE-2026-37431 | Beauty Parlour Management System SQL注入漏洞 | |
| CVE-2026-38360 | dash-uploader 路径遍历漏洞 | |
| CVE-2026-29972 | nanoMODBUS 安全漏洞 | |
| CVE-2026-29975 | Lightweight JSON text parser 安全漏洞 | |
| CVE-2026-29974 | minmea 安全漏洞 |
Showing top 20 of 40 CVEs. View all on vendor page → →
No comments yet