CVE-2025-70121: High severity free5gc Free5gc vulnerability
An array index out of bounds vulnerability in the AMF component of free5GC v4.0.1 allows remote attackers to cause a denial of service via a crafted 5GS Mobile Identity in a NAS Registration Request message. The issue occurs in the GetSUCI method (NASMobileIdentity5GS.go) when accessing index 5 of a 5-element array, leading to a runtime panic and AMF crash.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-70121?
CVE-2025-70121 is classified as a high severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2025-70121?
To fix CVE-2025-70121, update the free5GC software to the latest version where the vulnerability is addressed.
What component is affected by CVE-2025-70121?
CVE-2025-70121 affects the AMF component of free5GC version 4.0.1.
How does CVE-2025-70121 allow an attack?
CVE-2025-70121 allows remote attackers to exploit an array index out of bounds vulnerability, leading to a denial of service.
What type of request triggers CVE-2025-70121?
CVE-2025-70121 is triggered by a crafted 5GS Mobile Identity in a NAS Registration Request message.