CVE-2026-2525: Free5GC PFCP UDP Endpoint denial of service
A vulnerability has been found in Free5GC up to 4.1.0. This affects an unknown function of the component PFCP UDP Endpoint. Such manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2525?
CVE-2026-2525 is classified as a denial of service vulnerability, which allows an attacker to disrupt service to users.
How do I fix CVE-2026-2525?
To mitigate CVE-2026-2525, upgrade Free5GC to a version later than 4.1.0 to avoid the vulnerability.
Who is affected by CVE-2026-2525?
CVE-2026-2525 affects all users of Free5GC versions up to and including 4.1.0 who utilize the PFCP UDP Endpoint component.
Can CVE-2026-2525 be exploited remotely?
Yes, CVE-2026-2525 can be exploited remotely, making it a serious concern for all affected systems.
What component is involved in CVE-2026-2525?
CVE-2026-2525 involves the PFCP UDP Endpoint component of Free5GC.