CVE-2025-70123

7.5

free5GC · free5GC

A protocol compliance flaw in the free5GC User Plane Function allows unauthenticated remote attackers to cause a denial of service via malformed PFCP requests.

Executive summary

A critical denial of service vulnerability in free5GC v4.0.1 exposes core network components to service disruption through malformed protocol requests.

Vulnerability

This is an input validation and protocol compliance issue where the User Plane Function (UPF) fails to correctly handle malformed PFCP Association Setup Requests. An unauthenticated remote attacker can trigger a cascading failure that disconnects the Session Management Function (SMF) and degrades network service.

Business impact

The ability for an unauthenticated attacker to cause a denial of service against a core network function represents a significant operational risk. With a CVSS score of 7.5, this vulnerability could lead to widespread service outages for subscribers and infrastructure instability. Successful exploitation disrupts the control plane, potentially resulting in prolonged downtime and costly service restoration efforts.

Remediation

Immediate Action: Since a specific patch version is currently unknown, administrators should monitor the official free5GC GitHub repository for updates and restrict network access to the UPF interface to trusted sources only.

Proactive Monitoring: Security teams should monitor network logs for anomalous PFCP traffic patterns and alert on unexpected disconnections between the SMF and UPF components.

Compensating Controls: Implement strict network segmentation and firewall rules to ensure that only authorized control plane elements can communicate with the UPF, thereby reducing the attack surface.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit available in the provided data.

Analyst recommendation

Given the potential for service-wide disruption and the existence of a proof-of-concept, this vulnerability must be treated with high priority. Organizations utilizing free5GC v4.0.1 must implement strict network access controls immediately and prioritize the deployment of vendor-supplied patches as soon as they become available.

More free5GC CVEs

Sources