Exploitability of malformed MobileIdentity5GS inputs accepted by the defective patch
Determine whether malformed pre-authentication NAS RegistrationRequest inputs containing violating MobileIdentity5GS values, which are silently accepted because the validation block in free5GC nas v1.2.3 is unreachable, are individually exploitable through downstream code.
References
The practical impact is the elimination of the intended defense-in-depth layer for a class of pre-authentication inputs whose individual exploitability remains an open question for downstream code.
— Drishti: AI-Led Human-Directed Vulnerability Auditing for 5G Cores
(2608.30112 - Ramachandran et al., 31 Aug 2026) in Appendix, Section “CVE-2025-69248 patch defect: line-by-line analysis,” paragraph “Why no live-stack reproduction was needed” (Appendix B)