PT-2026-21580 · Free5Gc · Free5Gc Udm
CVE-2025-69251
·
Publicado
2026-02-23
·
Atualizado
2026-02-25
CVSS v4.0
6.6
Média
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U |
Name of the Vulnerable Software and Affected Versions
free5gc UDM versions up to and including 1.4.1
Description
free5gc UDM provides Unified Data Management for free5GC, an open-source 5G mobile core network project. A flaw exists where attackers can inject control characters, such as %00, into the
ueId parameter. This injection causes internal URL parsing errors (net/url: invalid control character), potentially revealing system implementation details and aiding in service fingerprinting. The Nudm UECM service within free5GC UDM is potentially affected in all deployments.Recommendations
Apply the fix available in free5gc/udm pull request 76.
Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Free5Gc Udm