Skip to main content
Vulnerability Database/CVE-2025-60633

CVE-2025-60633: Free5GC DoS Vulnerability via API

CVE-2025-60633 is a denial of service vulnerability in Free5GC that allows attackers to disrupt network operations through the Nudm_SubscriberDataManagement API. This post covers technical details, affected versions, and mitigation.

Published:

CVE-2025-60633 Overview

CVE-2025-60633 is a denial-of-service vulnerability affecting Free5GC, an open-source 5G core network implementation. The flaw exists in the Nudm_SubscriberDataManagement API exposed by the Unified Data Management (UDM) network function. An authenticated attacker with low privileges can send crafted requests over the network to disrupt availability of the subscriber data management service. The vulnerability affects Free5GC versions 4.0.0 and 4.0.1 and is categorized under [CWE-1287] (Improper Validation of Specified Type of Input). Successful exploitation does not impact confidentiality or integrity, but produces a high availability impact on the targeted 5G core deployment.

Critical Impact

An authenticated network attacker can disrupt subscriber data management services in Free5GC 4.0.0 and 4.0.1, impacting availability of 5G core signaling.

Affected Products

  • Free5GC 4.0.0
  • Free5GC 4.0.1
  • Deployments exposing the Nudm_SubscriberDataManagement API

Discovery Timeline

  • 2025-11-24 - CVE-2025-60633 published to the National Vulnerability Database (NVD)
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-60633

Vulnerability Analysis

Free5GC implements the 3GPP Service-Based Architecture (SBA) for 5G core networks. The Unified Data Management (UDM) function exposes the Nudm_SubscriberDataManagement service, which other network functions call to retrieve subscriber profiles, session management subscription data, and access data. The vulnerability stems from improper validation of input supplied to this API. When a malformed or unexpected request structure reaches the service handler, the UDM process enters a failure state that interrupts request processing. This leads to a denial-of-service condition against subscriber data operations in the 5G core.

Root Cause

The underlying weakness maps to [CWE-1287], Improper Validation of Specified Type of Input. The UDM service handler accepts input without enforcing the expected type or structural constraints defined by the Nudm interface. Fields that should be strictly typed or bounded are processed without sufficient guard checks. The resulting error path terminates or stalls the request flow instead of returning a graceful protocol error.

Attack Vector

Exploitation requires network reachability to the UDM service and valid low-privilege credentials to authenticate against the Service-Based Interface. The attacker sends a crafted request to the Nudm_SubscriberDataManagement endpoint. Because this interface is consumed by functions such as the AMF, SMF, and AUSF, disruption cascades across session establishment and registration flows. User interaction is not required, and no scope change occurs.

Technical specifics are tracked in the Free5GC project. See Free5GC Issue #700, Issue #701, Issue #702, and Issue #703.

Detection Methods for CVE-2025-60633

Indicators of Compromise

  • Unexpected restarts or crash loops of the UDM container or process in the 5G core
  • Spikes in HTTP/2 request failures or 5xx responses on the Nudm_SubscriberDataManagement endpoint
  • Registration or PDU session failures across multiple subscribers correlated with UDM errors

Detection Strategies

  • Inspect UDM application logs for parse errors, panics, or stack traces triggered by Nudm requests
  • Correlate NRF health check failures for the UDM instance with inbound SBI traffic patterns
  • Baseline normal request shapes to Nudm endpoints and alert on structural anomalies in JSON payloads

Monitoring Recommendations

  • Monitor UDM pod or process uptime, restart count, and memory state in Kubernetes or bare-metal deployments
  • Enable request-level audit logging on the SBI interface including source NF identity and request URI
  • Forward 5G core telemetry into a centralized data lake for correlation across AMF, SMF, AUSF, and UDM

How to Mitigate CVE-2025-60633

Immediate Actions Required

  • Inventory all Free5GC deployments and identify instances running versions 4.0.0 or 4.0.1
  • Restrict network reachability to the UDM Service-Based Interface so only authorized network functions can connect
  • Review and rotate NF client credentials used to authenticate against the UDM API
  • Enable rate limiting and request validation at any service mesh or API gateway in front of UDM

Patch Information

No fixed version is listed in the NVD record at the time of publication. Monitor the Free5GC GitHub repository and the referenced issue trackers for an updated release that addresses the input validation flaw in the Nudm_SubscriberDataManagement handler. Upgrade to the patched release once published and validate recovery through functional testing of registration and session flows.

Workarounds

  • Place a validating reverse proxy or service mesh policy in front of UDM to reject malformed Nudm requests
  • Segment the SBI network so only trusted network functions can reach UDM endpoints
  • Apply mutual TLS and strict NF-to-NF authorization policies to limit which clients can invoke Nudm_SubscriberDataManagement
  • Implement automated restart and health checks for the UDM service to shorten availability impact during attempted exploitation

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.