CVE-2025-66720 is a high-severity null pointer dereference vulnerability affecting free5gc pcf version 1.4.0, specifically within the HandleDeletePoliciesPolAssoId function. With a CVSS score of 7.5, this vulnerability can be exploited remotely without authentication, leading to a denial-of-service condition. While there are no known public exploits or Metasploit/Nuclei modules, the vulnerability has garnered significant community discussion, indicating potential interest from threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.4.0CPE matchmatch criteria | cpe:2.3:a:free5gc:pcf:1.4.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.