CVE-2026-30072
nicheNULL Pointer Dereference DoS in free5GC 5G Core CDR Processing (v4.0.1)
CVE-2026-30072 is a NULL pointer dereference (CWE-476) in the CDR (call/charging detail record) processing path of free5GC v4.0.1, an open-source 5G core network. A remote, unauthenticated attacker can send a crafted payload that reaches the CDR processing code and triggers the NULL dereference, crashing the affected network function. The impact is availability only (CVSS 3.1 7.5 High, A:H with no confidentiality or integrity impact): a successful attack causes a denial of service of the free5GC component handling CDRs, which can disrupt the core network services it supports. Anyone running free5GC v4.0.1 with CDR processing enabled — typically research testbeds, labs, and private 5G network deployments — is affected; no fixed version is stated in the available data. As of now there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.4% chance of exploitation in the next 30 days, so exploitation has not been observed.
What to do: Watch the free5GC project for a patched release and upgrade from v4.0.1 as soon as a fix is published, since no fixed version is specified in the current data. Until then, limit network access to the core's service interfaces (e.g., the SBI endpoints of the network function handling CDRs) to trusted peers, and disable CDR generation if it is not required. Check your running build to confirm whether you are on v4.0.1 and re-test after upgrading.
| free5GC (open-source project) free5GC 5G Core | v4.0.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A NULL pointer dereference in the CDR processing path of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted payload.
- Weakness
- CWE-476
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.