


Perceptive Security
SOC/SIEM Consultancy

Ella Core is a 5G core designed for private networks. Prior to 1.10.0, a radio with a valid NG Setup can send a forged PDUSessionResourceSetupResponse carrying …
Published:
26 mei 2026 om 22:00:00
Alert date:
27 mei 2026 om 21:06:41
Source:
nvd.nist.gov
Network Infrastructure, Mobile & IoT, Critical Infrastructure
Ella Core, a 5G core network solution for private networks, contains a vulnerability prior to version 1.10.0. The vulnerability allows a radio with valid NG Setup to send forged PDUSessionResourceSetupResponse messages carrying any UE's AMF-UE-NGAP-ID. The system fails to verify that messages arrive on the correct SCTP association bound to the UE's logical NG-connection, leading to creation of GTP tunnels towards unauthorized radios. This represents a significant authentication bypass in 5G network infrastructure that could enable traffic redirection attacks. The vulnerability has been patched in version 1.10.0.
Technical details
Mitigation steps:
Affected products:
Ella Core
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-44473
https://github.com/ellanetworks/core/security/advisories/GHSA-qfxw-v8qx-vj3v
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
