PT-2026-21562 · Free5Gc · Free5Gc Udr

Publicado

2026-02-23

·

Atualizado

2026-02-25

·

CVE-2025-69208

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions free5GC UDR versions prior to 1.4.1
Description The free5GC UDR, a user data repository for the free5GC 5G mobile core network project, contains an Improper Error Handling issue that can lead to Information Exposure. Deployments utilizing the Nnef PfdManagement service may be affected. The NEF component reveals internal parsing errors to remote clients, potentially aiding attackers in fingerprinting the server software and understanding its logic flows. The vulnerability is due to the component reliably leaking internal parsing errors, such as invalid characters, to remote clients.
Recommendations Update to version 1.4.1 or later.

Exploit

Correção

Generation of Error Message Containing Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-69208
GHSA-F3PC-W7JP-4JH2

Produtos afetados

Free5Gc Udr