---
id: CVE-2025-15685
title: A flaw has been found in Open5GS up to 2.7.1
summary: >-
  A flaw has been found in Open5GS up to 2.7.1. Affected by this vulnerability
  is an unknown functionality of the component freeDiameter. This manipulation
  causes memory corruption. The attack is possible to be carried out remotely.
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-119
published: '2026-08-12'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T11:10:00.150'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15685'
references:
  - url: 'https://github.com/open5gs/open5gs/'
    label: cna@vuldb.com
  - url: 'https://github.com/open5gs/open5gs/issues/4156'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2025-15685'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/867103'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/387278'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/387278/cti'
    label: cna@vuldb.com
  - url: 'https://github.com/open5gs/open5gs/issues/4156'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
ingestedAt: '2026-09-29T11:32:41.232Z'
epss: 0.00399
epssPercentile: 0.31519
---

## Overview

A flaw has been found in Open5GS up to 2.7.1. Affected by this vulnerability is an unknown functionality of the component freeDiameter. This manipulation causes memory corruption. The attack is possible to be carried out remotely.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
