CVE-2026-2525
- EPSS 0.07%
- Veröffentlicht 16.02.2026 01:02:06
- Zuletzt bearbeitet 19.02.2026 19:48:12
A vulnerability has been found in Free5GC up to 4.1.0. This affects an unknown function of the component PFCP UDP Endpoint. Such manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the publi...
CVE-2025-70123
- EPSS 0.19%
- Veröffentlicht 13.02.2026 00:00:00
- Zuletzt bearbeitet 18.02.2026 15:40:29
An improper input validation and protocol compliance vulnerability in free5GC v4.0.1 allows remote attackers to cause a denial of service. The UPF incorrectly accepts a malformed PFCP Association Setup Request, violating 3GPP TS 29.244. This places t...
CVE-2025-70122
- EPSS 0.13%
- Veröffentlicht 13.02.2026 00:00:00
- Zuletzt bearbeitet 18.02.2026 15:40:09
A heap buffer overflow vulnerability in the UPF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted PFCP Session Modification Request. The issue occurs in the SDFFilterFields.UnmarshalBinary function (sdf-fi...
CVE-2025-70121
- EPSS 0.14%
- Veröffentlicht 13.02.2026 00:00:00
- Zuletzt bearbeitet 18.02.2026 15:45:58
An array index out of bounds vulnerability in the AMF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted 5GS Mobile Identity in a NAS Registration Request message. The issue occurs in the GetSUCI method (NA...
CVE-2026-1976
- EPSS 0.08%
- Veröffentlicht 06.02.2026 03:15:49
- Zuletzt bearbeitet 09.02.2026 15:04:08
A weakness has been identified in Free5GC up to 4.1.0. Affected is the function SessionDeletionResponse of the component SMF. This manipulation causes null pointer dereference. The attack is possible to be carried out remotely. The exploit has been m...
CVE-2026-1975
- EPSS 0.08%
- Veröffentlicht 06.02.2026 03:15:49
- Zuletzt bearbeitet 09.02.2026 15:15:28
A security flaw has been discovered in Free5GC up to 4.1.0. This impacts the function identityTriggerType of the file pfcp_reports.go. The manipulation results in null pointer dereference. The attack can be executed remotely. The exploit has been rel...
CVE-2026-1974
- EPSS 0.07%
- Veröffentlicht 06.02.2026 02:16:05
- Zuletzt bearbeitet 09.02.2026 15:47:30
A vulnerability was identified in Free5GC up to 4.1.0. This affects the function ResolveNodeIdToIp of the file internal/sbi/processor/datapath.go of the component SMF. The manipulation leads to denial of service. Remote exploitation of the attack is ...
CVE-2026-1973
- EPSS 0.08%
- Veröffentlicht 06.02.2026 02:16:05
- Zuletzt bearbeitet 09.02.2026 15:48:21
A vulnerability was determined in Free5GC up to 4.1.0. The impacted element is the function establishPfcpSession of the component SMF. Executing a manipulation can lead to null pointer dereference. The attack may be launched remotely. The exploit has...
CVE-2026-1684
- EPSS 0.11%
- Veröffentlicht 30.01.2026 14:32:07
- Zuletzt bearbeitet 23.02.2026 10:16:18
A vulnerability was found in Free5GC SMF up to 4.1.0. Affected by this issue is the function HandleReports of the file /internal/context/pfcp_reports.go of the component PFCP UDP Endpoint. The manipulation results in denial of service. The attack can...
CVE-2026-1683
- EPSS 0.06%
- Veröffentlicht 30.01.2026 14:16:07
- Zuletzt bearbeitet 23.02.2026 10:16:18
A vulnerability has been found in Free5GC SMF up to 4.1.0. Affected by this vulnerability is the function HandlePfcpSessionReportRequest of the file internal/pfcp/handler/handler.go of the component PFCP. The manipulation leads to denial of service. ...