← All Advisories

Ericsson Packet Core Controller command injection executes arbitrary code as root before version 1.38

Last refreshed2026-09-30

Status: NEW  |  Advisory ID: CVE-2025-59172

Key Details

CVECVE-2025-59172
CVSS Score / Version8.5 (High) / CVSS v4.0
Updated2026-07-28
Classified asCWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'))

What to Know

Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-59172
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-59172