EXPLORE DIRECTORY
LAST SYNCHRONIZED: 2026-08-30TLP:CLEAR
vulnerabilitycritical
Telecom SS7/Diameter Core Gateway Packet Deserialization RCE
EXECUTIVE INTELLIGENCE SUMMARY
Flaw in carrier-grade Signalling System 7 (SS7) and Diameter routing gateways enabling remote unauthenticated actors to execute arbitrary code within core cellular interconnects.
Improper length verification during ASN.1 MAP (Mobile Application Part) parameter decoding allows specially crafted international roaming handshake packets to corrupt the call processing daemon memory space. Exploitation allows real-time SMS interception, IMSI geolocation tracking, and arbitrary command execution on national cellular backbone nodes.
TECHNICAL EXPLOITATION MATRIX
CVSS v4.0 SCORE
10.0 / 10.0
CRITICAL BASE SEVERITY
EPSS EXPLOIT PROBABILITY
94.5%
PERCENTILE 98.4
EXPLOITED IN THE WILD
CONFIRMED
CISA KEV CATALOG
AFFECTED SOFTWARE BUILDS
CarrierCore Roaming Gateway OS (Multi-Vendor Telecom Stacks)
AFFECTED: v12.4 - v14.2
FIXED IN: v14.3-hotfix
RECOMMENDED REMEDIATION & MITIGATIONS
- [1]Enforce strict GTP/Diameter firewalling at all international peering interconnect points.
- [2]Drop unauthenticated SendRoutingInfoForSM (SRI-SM) packets from non-whitelisted Global Title (GT) prefixes.
SOURCE CITATIONS & ATTESTATIONS (1)
ENISA Urgent Alert: Telecom Core Interconnect FlawsENISA
Signaling Security in European Telecommunication Backbones
TELEMETRY CARDID: cve-2026-1194
ENTITY TYPE
vulnerability
INDEXED TAGS
#telecom#ss7#diameter#cellular_core#zero_day#carrier_security
CONNECTED ENTITIES (2)VIEW IN GRAPH →