PT-2026-21582 · Free5Gc · Free5Gc

Published

2026-02-24

·

Updated

2026-02-25

·

CVE-2025-69253

CVSS v4.0

6.6

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions free5GC versions up to and including 1.4.1
Description free5GC is an open-source project for 5G mobile core networks. Improper error handling with information exposure exists in the User Data Repository component. The NEF component leaks internal parsing error details to remote clients, potentially aiding attackers in service fingerprinting. Deployments using the Nnef PfdManagement service may be vulnerable.
Recommendations Apply the patch available in free5gc/udr pull request 56.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2025-69253
GHSA-CJ2H-X8QM-XGWC

Affected Products

Free5Gc