ZeroHour

CVE-2026-30072

niche

NULL Pointer Dereference DoS in free5GC 5G Core CDR Processing (v4.0.1)

CVSS 3.1
7.5 high
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-30072 is a NULL pointer dereference (CWE-476) in the CDR (call/charging detail record) processing path of free5GC v4.0.1, an open-source 5G core network. A remote, unauthenticated attacker can send a crafted payload that reaches the CDR processing code and triggers the NULL dereference, crashing the affected network function. The impact is availability only (CVSS 3.1 7.5 High, A:H with no confidentiality or integrity impact): a successful attack causes a denial of service of the free5GC component handling CDRs, which can disrupt the core network services it supports. Anyone running free5GC v4.0.1 with CDR processing enabled — typically research testbeds, labs, and private 5G network deployments — is affected; no fixed version is stated in the available data. As of now there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.4% chance of exploitation in the next 30 days, so exploitation has not been observed.

What to do: Watch the free5GC project for a patched release and upgrade from v4.0.1 as soon as a fix is published, since no fixed version is specified in the current data. Until then, limit network access to the core's service interfaces (e.g., the SBI endpoints of the network function handling CDRs) to trusted peers, and disable CDR generation if it is not required. Check your running build to confirm whether you are on v4.0.1 and re-test after upgrading.

Affected
free5GC (open-source project) free5GC 5G Corev4.0.1
Estimated exposure
niche≈ thousands of deployments at most (labs, academic testbeds, and private 5G networks running free5GC) — free5GC is an open-source 5G core used mainly in research testbeds, labs, and small private 5G networks rather than at carrier scale, and it publishes no install counts, so the affected population is plausibly in the thousands or fewer —…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A NULL pointer dereference in the CDR processing path of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted payload.

Weakness
CWE-476
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.