Tag
critical
advisory
free5GC SMF Unauthenticated UPI Access
2 rules 1 TTP 2 IOCsfree5GC's Session Management Function (SMF) UPI interface lacks authentication, allowing unauthenticated network attackers to read/write/delete UP-node and link topology data via exposed APIs.
SMF
5G
Authentication Bypass
free5GC
UPI
CVE-2026-44329
2r
1t
2i
medium
threat
free5GC SMF Unauthenticated Process-Kill Denial-of-Service via UPI Endpoint
2 rules 1 TTP 1 IOCfree5GC's SMF is vulnerable to an unauthenticated denial-of-service attack where a crafted POST request to the `/upi/v1/upNodesLinks` endpoint can trigger a `Fatalf` call, terminating the entire SMF process, effectively disrupting network services.
SMF
free5GC
DoS
unauthenticated
UPI
CVE-2026-44321
2r
1t
1i