← Back to overview

CVE-2026-30062 is a vulnerability affecting free5gc v4.0.1, an open-source 5G core network implementation. The flaw resides in the NGAP (Next Generation Application Protocol) handler, which is responsible for processing communication between the 5G core and base stations. Attackers can exploit this vulnerability by sending a specially crafted NAS (Non-Access Stratum) PDU (Protocol Data Unit) to trigger a Denial of Service condition. Successful exploitation could cause the free5gc service to crash or become unresponsive, disrupting 5G core network operations. The issue was reported via the free5gc GitHub issue tracker. This vulnerability is particularly significant as free5gc is widely used in research, testing, and potentially production 5G deployments. No authentication appears to be required to send malformed NGAP/NAS messages, broadening the attack surface.

Affected products

  • free5gc v4.0.1

Related CVE's

  • CVE-2026-30062

Categories

  • Critical Infrastructure
  • Emerging Technologies
  • Network Infrastructure