Executive brief
The Session Management Function (SMF) in free5GC, which manages user data sessions in a 5G network, contains a security flaw where its topology management interface does not require authentication. This allows any attacker with network access to the management interface to view, modify, or delete the network's internal structure. Such an exploit could lead to the redirection of user traffic to malicious servers or a complete disruption of mobile data services.
Technical details
The Session Management Function (SMF) in free5GC fails to apply OAuth2/bearer-token authentication middleware to the User Plane Information (UPI) route group. While other sibling route groups like 'nsmf-oam' are protected, the UPI group is mounted without these security checks in 'NFs/smf/internal/sbi/server.go'. An unauthenticated attacker can reach the Service Based Interface (SBI) and interact with endpoints such as '/upi/v1/upNodesLinks' via GET, POST, and DELETE methods. This allows for unauthorized disclosure of the User Plane topology, injection of malicious User Plane Function (UPF) nodes to hijack PDU sessions, or deletion of legitimate nodes to cause a denial of service. The vulnerability is fixed in version 1.4.3.
Affected products
- free5GC smf < 1.4.3
Timeline
- 2026-03-13: other: Vulnerability validated in Docker lab environment
- 2026-05-08: advisory: GitHub Advisory published
- 2026-05-27: other: NVD publication date