CVE-2025-57446

7.5

O-RAN Software Community · Near Realtime RIC ric-plt-submgr

A denial of service vulnerability in the O-RAN Near Realtime RIC Subscription Manager component allows remote, unauthenticated attackers to crash the service via a crafted API request.

Executive summary

A remote denial of service vulnerability in the O-RAN Near Realtime RIC J-Release environment poses a significant risk to service availability through unauthenticated exploitation.

Vulnerability

This vulnerability is a denial of service flaw located within the Subscription Manager API component. It allows remote, unauthenticated attackers to disrupt service operations by sending a specially crafted request.

Business impact

The ability for an unauthenticated remote attacker to trigger a denial of service directly impacts the availability of the O-RAN Near Realtime RIC platform. Given the CVSS score of 7.5, this high-severity flaw could lead to critical service outages in network-critical infrastructure, resulting in operational disruption and potential failure of dependent telecommunications functions.

Remediation

Immediate Action: Monitor the vendor advisory portal for the release of an official patch for the J-Release environment and apply it as soon as it becomes available.

Proactive Monitoring: Review system and API access logs for anomalous, malformed, or high-frequency requests directed toward the Subscription Manager API endpoint.

Compensating Controls: Implement rate limiting or ingress filtering at the network perimeter to restrict access to the Subscription Manager API to authorized IP addresses only.

Exploitation status

Public Exploit Available: Yes — a public proof-of-concept exists as documented in the researcher's repository linked in the official CVE references.

Analyst recommendation

Organizations utilizing the O-RAN Near Realtime RIC J-Release should prioritize the implementation of network-level access controls to isolate the Subscription Manager API. Because a public proof-of-concept is available, the risk of exploitation is elevated. Administrators must remain vigilant for vendor updates and apply the necessary patches immediately upon release to restore service stability and security.

Sources