CVE-2025-69252General(free5gc / udm)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.1 have a NULL Pointer Dereference vulnerability. Remote unauthenticated attackers can trigger a service panic (Denial of Service) by sending a crafted PUT request with an unexpected ueId, crashing the UDM service. All deployments of free5GC using the UDM component may be affected. free5gc/udm pull request 76 contains a fix for the issue. No direct workaround is available at the application level. Applying the official patch is recommended.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • udm

Threat summary

  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 2 mentions (2026-02-24); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
udm

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-02-24: 2Mentions · 2026-02-27: 1Mentions · 2026-02-28: 1Mentions · 2026-03-01: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-27: 1Technical Details · 2026-02-28: 1Technical Details · 2026-03-01: 102-2402-2702-2803-01
Signal classification2 categories
General
360.0%
Disclosure
240.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-242
Disclosure1General1
2026-02-271
General1
2026-02-281
Disclosure1
2026-03-011
General1
Full discourse5 posts
  • CRAC Learning - Tech@cracbot
    General

    CVE-2025-69252 (CVSS:6.6, HIGH) is Analyzed. free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile co..https://nvd.nist.gov/vuln/detail/CVE-2025-69252 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE‑2025‑69252 with its CVSS score but provides no further details or actionable information.

    0000081
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-69252 (CVSS:6.6, HIGH) is Analyzed. free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile co..https://nvd.nist.gov/vuln/detail/CVE-2025-69252 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2025-69252 is reported with a CVSS score of 6.6 (HIGH), but no PoC, exploitation, or patch information is provided.

    0000098
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2025-69252 (CVSS:6.6, HIGH) is Analyzed. free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile co..https://nvd.nist.gov/vuln/detail/CVE-2025-69252 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post simply references CVE-2025-69252 with its CVSS score and links to the NVD page, without discussing exploitation, patches, or proofs of concept.

    0000030
    173 followersView on X
  • CVE@CVEnew
    General

    CVE-2025-69252 free5gc UDM provides Unified Data Management (UDM) for free5GC, an open-source project for 5th generation (5G) mobile core networks. Versions up to and including 1.4.… https://www.cve.org/CVERecord?id=CVE-2025-69252

    Post summary

    The text merely references CVE-2025-69252 affecting free5gc UDM, without providing additional technical or operational details.

    00000165
    56.5K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2025-69252 📊 Severity: 6.6 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-69252 #CVE-2025-69252 #CVE #Medium #CyberSecurity #InfoSec https://t.co/z2vvMnItgy

    Post summary

    A new CVE-2025-69252 has been announced with a medium severity score of 6.6, affecting multiple unspecified products; no PoC, exploit, or patch details are provided.

    0000041
    57 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfree5gcudm-go-

Explore more