CVE-2025-69208Disclosure(free5gc / udr)

LOWCVSS 5.3 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. Versions prior to 1.4.1 contain an Improper Error Handling vulnerability with Information Exposure. All deployments of free5GC using the Nnef_PfdManagement service may be affected. The NEF component reliably leaks internal parsing errors (e.g., invalid character 'n' after top-level value) to remote clients. This can aid attackers in fingerprinting server software and logic flows. Version 1.4.1 fixes the issue. There is no direct workaround at the application level. The recommended mitigation is to apply the provided patch.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-209

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • udr

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
udr

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-24: 3Technical Details · 2026-02-24: 202-24
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets2 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-69208 Information Exposure Vulnerability in free5GC UDR Versions Prior to 1.4.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-69208

    Post summary

    A new information exposure vulnerability (CVE-2025-69208) affecting free5GC UDR versions prior to 1.4.1 has been disclosed.

    1001056
    4.0K followersView on X
  • transilienceai@transilienceai
    Disclosure

    @VulmonFeeds 🚨 **CVE-2025-69208** is an **Information Exposure** vulnerability due to **Improper Error Handling** in **free5GC UDR versions prior to 1.4.1**. It affects all deployments using the **Nnef_PfdManagement service**. #CyberSecurity #Vulnerability

    Post summary

    CVE-2025-69208 is an information exposure flaw in free5GC UDR versions before 1.4.1 caused by improper error handling, impacting deployments that use the Nnef_PfdManagement service.

    1000047
    319 followersView on X
  • CVE@CVEnew
    General

    CVE-2025-69208 free5GC UDR is the user data repository (UDR) for free5GC, an an open-source project for 5th generation (5G) mobile core networks. Versions prior to 1.4.1 contain an … https://www.cve.org/CVERecord?id=CVE-2025-69208

    Post summary

    The text briefly references CVE-2025-69208 affecting free5GC UDR in versions before 1.4.1, but provides no further details.

    00000550
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfree5gcudr-go-

Explore more