CVE-2025-66719: Critical severity free5gc Free5gc NRF vulnerability
An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck() function in file internal/sbi/processor/accesstoken.go bypasses all scope validation when the attacker uses a crafted targetNF value. This allows attackers to obtain an access token with any arbitrary scope.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66719?
CVE-2025-66719 has a high severity due to its potential to allow unauthorized access through an access token bypass.
How do I fix CVE-2025-66719?
To fix CVE-2025-66719, update to the latest version of Free5GC where the scope validation issue has been addressed.
What component of Free5GC is affected by CVE-2025-66719?
CVE-2025-66719 specifically affects the access-token generation logic in the Free5GC NRF component.
Can CVE-2025-66719 lead to data exposure?
Yes, CVE-2025-66719 can lead to data exposure by allowing attackers to bypass access controls.
When was CVE-2025-66719 discovered?
CVE-2025-66719 was discovered in Free5GC NRF version 1.4.0.