PT-2026-64915 · Ericsson · Packet Core Controller

·

CVE-2025-59172

·

Published

2026-07-27

·

Updated

2026-07-27

CVSS v4.0

8.5

High

VectorAV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Ericsson Packet Core Controller (PCC) versions prior to 1.38
Description An Improper Neutralization of Special Elements issue allows an attacker to execute arbitrary code with root privileges.
Recommendations Update Ericsson Packet Core Controller (PCC) to version 1.38 or later.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-59172

Affected Products

Packet Core Controller