CVE-2026-75438
Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_parse() function
CVSS
7.5
High
EPSS
0.3%
p20
KEV
—
Exploit Today
6
0-100
Published: Sep 4, 2026 · Last modified: Sep 8, 2026 · CWE-120
0.3%EPSS · 30 days0.3%
2026-09-052026-09-07
Buffer Overflow vulnerability in Open5GS v2.7.7 allows a remote attacker to cause a denial of service via the ogs_sbi_time_parse() function
- gist.github.comhttps://gist.github.com/hackeryounow/c299d593b89fd6487cab4182c8aecabf
- github.comhttps://github.com/hackeryounow/5GCVulDB/blob/main/smf_crash_uelocationtimestamp.sh
- github.comhttps://github.com/hackeryounow/5GCVulDB/tree/main/CVE-2026-75438
- github.comhttps://github.com/open5gs/open5gs/commit/7227b2f5b254160286798e058c189224360d99fc
- github.comhttps://github.com/open5gs/open5gs/issues/4612
- github.comhttps://github.com/open5gs/open5gs/issues/4612
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-588397.8 HIG—
———In forEachLine of MountRegistry.cpp, there is a possible out of bounds read due to a buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.5hCVE-2026-588237.8 HIG—
———In stpropnci_process_std of stpropnci_std.cc, there is a possible memory safety issue due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.5hCVE-2026-552857.8 HIG—
———In openLogicalChannel of multiple files, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.5hCVE-2026-552778.0 HIG—
———In checkUiccListenConfigNeeded of RoutingManager.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation.5hCVE-2026-4475610.0 CRI—
——0A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.7hCVE-2026-861668.8 HIG39.5%
——12A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server. Executing a manipulation of the argument if can lead to buffer overflow. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.13h