CVE-2025-66719 Details
Description
An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck() function in file internal/sbi/processor/access_token.go bypasses all scope validation when the attacker uses a crafted targetNF value. This allows attackers to obtain an access token with any arbitrary scope.
A vulnerability in Free5GC Network Repository Function (NRF) version 1.4.0 allows for scope validation bypass in access token generation. The issue arises in the AccessTokenScopeCheck() function, where an early return is triggered if the targetNF is set to 'NRF'. This flaw enables attackers to request access tokens with arbitrary scopes, including sensitive ones, by manipulating the targetNF value. Exploitation could lead to unauthorized access to protected data and services.
Users can update to Free5GC NRF version 1.4.1, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/free5gc/free5gc/issues/736 | [email protected] | ExploitIssue Tracking |
| https://github.com/free5gc/nrf/pull/73 | [email protected] | Issue TrackingPatch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| free5gc nrf | 1.4.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 11, 2026 | Initial Analysis | [email protected] |
| Jan 23, 2026 | CVE Modified | CISA-ADP |
| Jan 23, 2026 | New CVE Received | [email protected] |