EricssonCVE-2025-59172
Ericsson Packet Core Controller (PCC): code execution
High8.5CVE-2025-59172 · Published Jul 27, 2026 · updated Jul 28, 2026
Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Packet Core Controller (PCC) Product | < 1.38 | 1.38 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
More Ericsson advisories
All Ericsson| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 28 | Ericsson CodeChecker: denial of service | Medium5.5 | 6.28.3 |
| Aug 26 | Ericsson CodeChecker: improper access control | Low1.2 | 6.28.3 |
| Jul 27 | Ericsson Packet Core Controller (PCC): system information exposure | Medium4.8 | 1.39 |
| Jul 27 | Ericsson Packet Core Controller (PCC): hard-coded credentials | Medium5.1 | 1.38 |
| Jul 27 | Ericsson Packet Core Controller (PCC): path traversal | Medium4.8 | 1.39 |
| Jul 27 | Ericsson Packet Core Controller (PCC): information disclosure in errors | Medium6.8 | 1.39 |