PT-2026-32975 · Unknown · Free5Gc Udr
Published
2026-04-14
·
Updated
2026-04-17
·
CVE-2026-40248
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
free5GC UDR service versions prior to 4.2.1
Description
An improper path validation issue exists in the UDR service. The handler for creating or updating Traffic Influence Subscriptions checks if the
influenceId path segment equals 'subs-to-notify', but fails to stop execution after sending an HTTP 404 response when validation fails. This allows an unauthenticated attacker with access to the 5G Service Based Interface to create or overwrite arbitrary Traffic Influence Subscriptions by providing any value for the influenceId path segment. This can lead to the injection of attacker-controlled notificationUri values and arbitrary SUPIs. The issue occurs in the function HandleApplicationDataInfluenceDataSubsToNotifySubscriptionIdPut() at the endpoint '/nudr-dr/v2/application-data/influenceData/{influenceId}/{subscriptionId}'.Recommendations
Update the UDR service to a version where the
HandleApplicationDataInfluenceDataSubsToNotifySubscriptionIdPut() function includes a return statement after the 404 response is sent.
Restrict access to the 5G Service Based Interface to authorized entities only to minimize the risk of exploitation.Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Free5Gc Udr