SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2025-59172

HIGH · CVSS 8.5 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

Ericsson Packet Core Controller (PCC) versions prior to 1.38 are vulnerable to an improper neutralization of special elements, which could enable an attacker to execute arbitrary code with root privileges. This vulnerability poses a significant risk to the integrity and security of network operations. Organizations utilizing affected versions of PCC should prioritize patching to mitigate potential exploitation.

CVE
CVE-2025-59172
Severity
HIGH
CVSS
8.5
EPSS
0.18%

Original NVD Description

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root.