DEFCON 3 · ELEVATED OBSERVATORY STATUS
04:24:00 UTC
EXPLORE DIRECTORY
LAST SYNCHRONIZED: 2026-08-30
vulnerabilitycritical

Telecom SS7/Diameter Core Gateway Packet Deserialization RCE

EXECUTIVE INTELLIGENCE SUMMARY

Flaw in carrier-grade Signalling System 7 (SS7) and Diameter routing gateways enabling remote unauthenticated actors to execute arbitrary code within core cellular interconnects.

Improper length verification during ASN.1 MAP (Mobile Application Part) parameter decoding allows specially crafted international roaming handshake packets to corrupt the call processing daemon memory space. Exploitation allows real-time SMS interception, IMSI geolocation tracking, and arbitrary command execution on national cellular backbone nodes.

TECHNICAL EXPLOITATION MATRIX
CVSS v4.0 SCORE
10.0 / 10.0
CRITICAL BASE SEVERITY
EPSS EXPLOIT PROBABILITY
94.5%
PERCENTILE 98.4
EXPLOITED IN THE WILD
CONFIRMED
CISA KEV CATALOG
AFFECTED SOFTWARE BUILDS
CarrierCore Roaming Gateway OS (Multi-Vendor Telecom Stacks)
AFFECTED: v12.4 - v14.2
FIXED IN: v14.3-hotfix
RECOMMENDED REMEDIATION & MITIGATIONS
  • [1]Enforce strict GTP/Diameter firewalling at all international peering interconnect points.
  • [2]Drop unauthenticated SendRoutingInfoForSM (SRI-SM) packets from non-whitelisted Global Title (GT) prefixes.
SOURCE CITATIONS & ATTESTATIONS (1)
ENISA Urgent Alert: Telecom Core Interconnect FlawsENISA

Signaling Security in European Telecommunication Backbones

TELEMETRY CARDID: cve-2026-1194
ENTITY TYPE
vulnerability
INDEXED TAGS
#telecom#ss7#diameter#cellular_core#zero_day#carrier_security