CVE-2025-70123Disclosure(free5gc / free5gc)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An improper input validation and protocol compliance vulnerability in free5GC v4.0.1 allows remote attackers to cause a denial of service. The UPF incorrectly accepts a malformed PFCP Association Setup Request, violating 3GPP TS 29.244. This places the UPF in an inconsistent state where a subsequent valid PFCP Session Establishment Request triggers a cascading failure, disrupting the SMF connection and causing service degradation.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • free5gc

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-13); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
free5gc

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-13: 2Mentions · 2026-02-18: 1Technical Details · 2026-02-13: 2Technical Details · 2026-02-18: 102-1302-18
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-132
Disclosure2
2026-02-181
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-70123 Denial of Service in Free5GC v4.0.1 via Malformed PFCP As... https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-70123 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    A denial‑of‑service vulnerability (CVE‑2025‑70123) affecting Free5GC v4.0.1 has been disclosed, triggered by malformed PFCP AS messages, but no PoC, exploit, or patch details are provided.

    0001031
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-70123 (CVSS:7.5, HIGH) is Undergoing Analysis. An improper input validation and protocol compliance vulnerability in free5GC v4.0.1 allows remote attackers to cause a ..https://nvd.nist.gov/vuln/detail/CVE-2025-70123 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE‑2025‑70123, detailing an improper input validation vulnerability in free5GC v4.0.1 with a high CVSS score, and notes it is still under analysis.

    0000044
    171 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-70123 An improper input validation and protocol compliance vulnerability in free5GC v4.0.1 allows remote attackers to cause a denial of service. The UPF incorrectly accepts… https://www.cve.org/CVERecord?id=CVE-2025-70123

    Post summary

    The text announces CVE-2025-70123, detailing an improper input validation in free5GC v4.0.1 that can lead to a denial of service, but provides no exploit, PoC, or patch information.

    00000245
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfree5gcfree5gc4.0.1--

Explore more