What is CVE-2025-59172?
Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an improper neutralization of special elements vulnerability. This allows a remote attacker to execute arbitrary code with root privileges. Immediate update to version 1.38 or later is recommended.
Azərbaycanca: Ericsson Packet Core Controller (PCC) 1.38 versiyasından əvvəlki versiyalarda xüsusi elementlərin düzgün neytrallaşdırılmaması zəifliyi aşkarlanıb. Bu qüsur uzaqdan hücum edən şəxsə root səviyyəsində ixtiyari kod icra etməyə imkan verir. Dərhal 1.38 və ya daha yuxarı versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which versions of Ericsson Packet Core Controller (PCC) are affected by CVE-2025-59172?
All versions prior to 1.38 are affected by this vulnerability.
With what privileges can a remote attacker execute arbitrary code by exploiting CVE-2025-59172?
A remote attacker can execute arbitrary code with root privileges.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.