CVE-2025-69232Disclosure(free5gc / go-upf)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

free5GC is an open-source project for 5th generation (5G) mobile core networks. free5GC go-upf versions up to and including 1.2.6, corresponding to free5gc smf up to and including 1.4.0, have an Improper Input Validation and Protocol Compliance vulnerability leading to Denial of Service. Remote attackers can disrupt core network functionality by sending a malformed PFCP Association Setup Request. The UPF incorrectly accepts it, entering an inconsistent state that causes subsequent legitimate requests to trigger SMF reconnection loops and service degradation. All deployments of free5GC using the UPF and SMF components may be affected. As of time of publication, a fix is in development but not yet available. No direct workaround is available at the application level. Applying the official patch, once released, is recommended.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • go-upf
  • smf

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-24); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
go-upfsmf

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-24: 2Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 102-2402-2702-28
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-242
Disclosure1General1
2026-02-271
General1
2026-02-281
Disclosure1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-69232 Denial of Service in free5GC UPF via Malformed PFCP Association Setup Request https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-69232

    Post summary

    A Denial of Service vulnerability (CVE-2025-69232) in free5GC UPF due to malformed PFCP Association Setup Requests has been disclosed.

    0001043
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-69232 (CVSS:2.7, HIGH) is Analyzed. free5GC is an open-source project for 5th generation (5G) mobile core networks. free5GC go-upf versions up to and includ..https://nvd.nist.gov/vuln/detail/CVE-2025-69232 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2025-69232 is a newly identified vulnerability in the free5GC go‑upf component, rated CVSS 2.7 (HIGH); the post lists the affect and score but does not provide any PoC, exploit, or patch information.

    0000082
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2025-69232 (CVSS:2.7, HIGH) is Analyzed. free5GC is an open-source project for 5th generation (5G) mobile core networks. free5GC go-upf versions up to and includ..https://nvd.nist.gov/vuln/detail/CVE-2025-69232 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE‑2025‑69232 with a CVSS score of 2.7 and identifies vulnerable free5GC go‑upf versions, but offers no further technical details, exploitation evidence, or remediation information.

    0000019
    173 followersView on X
  • CVE@CVEnew
    General

    CVE-2025-69232 free5GC is an open-source project for 5th generation (5G) mobile core networks. free5GC go-upf versions up to and including 1.2.6, corresponding to free5gc smf up to … https://www.cve.org/CVERecord?id=CVE-2025-69232

    Post summary

    The text only references CVE-2025-69232 and affected free5GC versions, lacking details on exploitation, patches, or technical specifics.

    00000508
    56.5K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appfree5gcgo-upf-go-
Appfree5gcsmf-go-

Explore more