Vulnerabilities (CVE)

Filtered by vendor Free5gc Subscribe
Filtered by product Nrf
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-66719 1 Free5gc 1 Nrf 2026-02-11 N/A 9.1 CRITICAL
An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck() function in file internal/sbi/processor/access_token.go bypasses all scope validation when the attacker uses a crafted targetNF value. This allows attackers to obtain an access token with any arbitrary scope.