Skip to content
EricssonCVE-2025-59172

Ericsson Packet Core Controller (PCC): code execution

High8.5CVE-2025-59172 · Published Jul 27, 2026 · updated Jul 28, 2026

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root.

Ericsson advisory

Affected versions

PackageAffectedFixed in
Packet Core Controller (PCC)
Product
< 1.381.38
Details and references
CVSS 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-78

More Ericsson advisories

All Ericsson

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.