logo

Analysis of multiple vulnerabilities in different open source BTS products

ID: 19cff383-d770-576e-a03d-4e1110ec96cf

STIX ID: report--19cff383-d770-576e-a03d-4e1110ec96cf

Feed Name: Zimperium Blog

Threat Score
75/100

Date Published: 2016-08-23

Date Updated: 2026-05-01

...
...

This report discloses multiple remote vulnerabilities in widely used GSM/UMTS BTS transceiver code: sockets are bound to INADDR_ANY allowing external access, the control channel contains a stack-based buffer overflow enabling potential remote code execution or DoS, and the control protocol is unauthenticated allowing remote operational control (power, tuning, identity). Affected products include OpenBTS, YateBTS, OpenBTS-UMTS, and Osmo-TRX; the report provides technical details, proof-of-concept behavior, a disclosure timeline (including some reverted fixes), and mitigation recommendations such as binding to localhost, firewalling ports, compile-time hardening, fixing buffer handling, and adding authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.