CVE-2025-70123

An improper input validation and protocol compliance vulnerability in free5GC v4.0.1 allows remote attackers to cause a denial of service. The UPF incorrectly accepts a malformed PFCP Association Setup Request, violating 3GPP TS 29.244. This places the UPF in an inconsistent state where a subsequent valid PFCP Session Establishment Request triggers a cascading failure, disrupting the SMF connection and causing service degradation.
References
Link Resource
https://github.com/free5gc/free5gc/issues/745 Exploit Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:free5gc:free5gc:4.0.1:*:*:*:*:*:*:*

History

17 Jun 2026, 10:03

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad de validación de entrada incorrecta y de cumplimiento de protocolo en free5GC v4.0.1 permite a atacantes remotos causar una denegación de servicio. El UPF acepta incorrectamente una solicitud de configuración de asociación PFCP malformada, violando 3GPP TS 29.244. Esto coloca al UPF en un estado inconsistente donde una solicitud posterior válida de establecimiento de sesión PFCP desencadena un fallo en cascada, interrumpiendo la conexión SMF y causando degradación del servicio.

18 Feb 2026, 15:40

Type Values Removed Values Added
First Time Free5gc free5gc
Free5gc
CPE cpe:2.3:a:free5gc:free5gc:4.0.1:*:*:*:*:*:*:*
References () https://github.com/free5gc/free5gc/issues/745 - () https://github.com/free5gc/free5gc/issues/745 - Exploit, Issue Tracking, Vendor Advisory

13 Feb 2026, 21:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-20

13 Feb 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-13 17:16

Updated : 2026-06-17 10:03


NVD link : CVE-2025-70123

Mitre link : CVE-2025-70123

CVE.ORG link : CVE-2025-70123


JSON object : View

Products Affected

free5gc

  • free5gc
CWE
CWE-20

Improper Input Validation