Vulnerability Description
free5gc v4.1.0 and before is vulnerable to Buffer Overflow. When AMF receives an UplinkRANConfigurationTransfer NGAP message from a gNB, the AMF process crashes.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Free5Gc | Free5Gc | <= 4.1.0 |
Related Weaknesses (CWE)
References
- https://gist.github.com/DDGod2025/5483d94b028d7a0c111ca23844e8a94dExploitThird Party Advisory
- https://github.com/free5gc/free5gc/issues/725ExploitIssue Tracking
FAQ
What is CVE-2025-63679?
CVE-2025-63679 is a vulnerability with a CVSS score of 7.5 (HIGH). free5gc v4.1.0 and before is vulnerable to Buffer Overflow. When AMF receives an UplinkRANConfigurationTransfer NGAP message from a gNB, the AMF process crashes.
How severe is CVE-2025-63679?
CVE-2025-63679 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-63679?
Check the references section above for vendor advisories and patch information. Affected products include: Free5Gc Free5Gc.