A recent study has identified 84 security vulnerabilities in the core networks of 4G and 5G technologies. These flaws, if exploited, can facilitate denial-of-service (DoS) attacks and session hijacking, where an attacker seizes control of a user’s network session. The research, conducted by Nanyang Technological University in Singapore, highlights critical issues within the signaling interfaces of both LTE and 5G core networks.
Key Findings of the Study
The researchers focused on various implementations of LTE and 5G, including Open5GS, OpenAirInterface, and others. They discovered recurring vulnerabilities rooted in “implicit trust” between core network functions. Historically, these networks relied on physical isolation to secure internal interfaces. However, the shift to cloud-native deployments has weakened this trust model, increasing the attack surface and making these vulnerabilities more accessible to attackers.
The study termed these vulnerabilities as “implicit trust errors” (iTrue) and developed a multi-agent system called iFinder to identify these flaws. This system categorizes known vulnerabilities and searches for new ones using a large language model (LLM). It also helps in creating proof-of-concept exploits to test and refine the understanding of these flaws.
Implications for Network Security
The vulnerabilities were found across seven open-source LTE/5G core network implementations, with 83 confirmed and 81 assigned CVE identifiers. The study also revealed that some of these flaws in 5G systems were inherited from older 4G technologies, underscoring the risks posed by legacy systems not adapting to modern deployments.
One example of a session hijacking attack involves exploiting duplicate Packet Detection Rule (PDR) IDs within PFCP Session Modification Request messages. This can lead to a user’s uplink traffic being rerouted to an attacker instead of its intended destination, posing significant security risks.
Vendor and Network Operator Responses
Addressing these vulnerabilities is crucial for vendors and network operators. One vendor, Dotouch, has already tackled a session hijacking flaw (CVE-2026-8233), while another unnamed major 5G carrier is still working on remediation. The study’s authors stress the urgency of addressing these issues, as the growing number of vulnerabilities signifies a broad security challenge rather than isolated bugs.
As these flaws expose critical weaknesses in telecommunications infrastructure, immediate action from vendors and network operators is imperative to safeguard against potential exploits.
