PT-2026-21580 · Free5Gc · Free5Gc Udm

CVE-2025-69251

·

Publicado

2026-02-23

·

Atualizado

2026-02-25

CVSS v4.0

6.6

Média

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions free5gc UDM versions up to and including 1.4.1
Description free5gc UDM provides Unified Data Management for free5GC, an open-source 5G mobile core network project. A flaw exists where attackers can inject control characters, such as %00, into the ueId parameter. This injection causes internal URL parsing errors (net/url: invalid control character), potentially revealing system implementation details and aiding in service fingerprinting. The Nudm UECM service within free5GC UDM is potentially affected in all deployments.
Recommendations Apply the fix available in free5gc/udm pull request 76.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-69251
GHSA-PWXH-4QH4-HGPQ

Produtos afetados

Free5Gc Udm