Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-44329 | 10.0 CRITICAL | free5GC: SMF UPI management interface lacks auth middleware; unauthenticated topology read |
| CVE-2026-44330 | 10.0 CRITICAL | free5GC: NEF nnef-pfdmanagement API is unauthenticated; forged bearer tokens can read PFD |
| CVE-2026-44326 | 9.4 CRITICAL | free5GC: NEF 3gpp-traffic-influence API is unauthenticated; missing or forged bearer token |
| CVE-2026-44315 | 9.4 CRITICAL | free5GC: NEF 3gpp-pfd-management API is unauthenticated; forged bearer tokens can create, |
| CVE-2026-42083 | 8.2 HIGH | free5GC: PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated |
| CVE-2026-44328 | 8.2 HIGH | free5GC: SMF UPI DELETE /upi/v1/upNodesLinks/{ref} panics on AN-node deletion via nil UPF |
| CVE-2026-44316 | 7.5 HIGH | free5GC: PCF npcf-smpolicycontrol POST /sm-policies panics on downstream UDR/OpenAPI 404 v |
| CVE-2026-44325 | 7.5 HIGH | free5GC: NRF POST /oauth2/token structured-form parser type-confusion panic family (Reflec |
| CVE-2026-44322 | 7.5 HIGH | free5GC: NEF 3gpp-pfd-management PATCH applications/{appId} panics on UDR access failure d |
| CVE-2026-44321 | 7.5 HIGH | free5GC: SMF UPI POST /upi/v1/upNodesLinks exits the SMF process on overlapping UE pools ( |
| CVE-2026-44319 | 7.5 HIGH | free5GC: NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-contr |
| CVE-2026-44320 | 7.3 HIGH | free5GC: NEF nnef-callback route group is unauthenticated; forged callback requests are ac |
| CVE-2026-44318 | 6.5 MEDIUM | free5GC: BSF concurrent PUT /nbsf-management/v1/subscriptions/{subId} crashes the BSF proc |
| CVE-2026-44324 | 6.5 MEDIUM | free5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing UE state via nil interface |
| CVE-2026-44317 | 6.5 MEDIUM | free5GC: PCF npcf-policyauthorization POST /app-sessions panics on suppFeat=1 with missing |
| CVE-2026-42081 | 6.1 MEDIUM | free5GC: UE Security Capability bypass on NGAP PathSwitchRequest |
| CVE-2026-44323 | 4.3 MEDIUM | free5GC: UDR nudr-dr DELETE amf-subscriptions panics on missing subsId when UE state exist |
| CVE-2026-42082 | 3.7 LOW | free5GC: Missing Concurrent NAS SMC Validation During NGAP Handover |
| CVE-2026-42459 | free5GC: Improper Input Validation and Generation of Error Message Containing Sensitive In |
No comments yet