Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
84 Security Flaws Uncovered in 4G and 5G Networks

84 Security Flaws Uncovered in 4G and 5G Networks

Posted on July 31, 2026 By CWS

A recent study has identified 84 security vulnerabilities in the core networks of 4G and 5G technologies. These flaws, if exploited, can facilitate denial-of-service (DoS) attacks and session hijacking, where an attacker seizes control of a user’s network session. The research, conducted by Nanyang Technological University in Singapore, highlights critical issues within the signaling interfaces of both LTE and 5G core networks.

Key Findings of the Study

The researchers focused on various implementations of LTE and 5G, including Open5GS, OpenAirInterface, and others. They discovered recurring vulnerabilities rooted in “implicit trust” between core network functions. Historically, these networks relied on physical isolation to secure internal interfaces. However, the shift to cloud-native deployments has weakened this trust model, increasing the attack surface and making these vulnerabilities more accessible to attackers.

The study termed these vulnerabilities as “implicit trust errors” (iTrue) and developed a multi-agent system called iFinder to identify these flaws. This system categorizes known vulnerabilities and searches for new ones using a large language model (LLM). It also helps in creating proof-of-concept exploits to test and refine the understanding of these flaws.

Implications for Network Security

The vulnerabilities were found across seven open-source LTE/5G core network implementations, with 83 confirmed and 81 assigned CVE identifiers. The study also revealed that some of these flaws in 5G systems were inherited from older 4G technologies, underscoring the risks posed by legacy systems not adapting to modern deployments.

One example of a session hijacking attack involves exploiting duplicate Packet Detection Rule (PDR) IDs within PFCP Session Modification Request messages. This can lead to a user’s uplink traffic being rerouted to an attacker instead of its intended destination, posing significant security risks.

Vendor and Network Operator Responses

Addressing these vulnerabilities is crucial for vendors and network operators. One vendor, Dotouch, has already tackled a session hijacking flaw (CVE-2026-8233), while another unnamed major 5G carrier is still working on remediation. The study’s authors stress the urgency of addressing these issues, as the growing number of vulnerabilities signifies a broad security challenge rather than isolated bugs.

As these flaws expose critical weaknesses in telecommunications infrastructure, immediate action from vendors and network operators is imperative to safeguard against potential exploits.

The Hacker News Tags:4G, 5G, cloud-native, core networks, Cybersecurity, DoS attacks, GTP-C, LTE, network operators, network security, PFCP, protocol tunneling, security vulnerabilities, session hijacking, Telecommunications

Post navigation

Previous Post: FBI Warns of North Korean IT Workers Using False Identities
Next Post: AI Powers Google Chrome Security with 1,072 Fixes

Related Posts

B Crypto Bust, Satellite Spying, Billion-Dollar Smishing, Android RATs & More $15B Crypto Bust, Satellite Spying, Billion-Dollar Smishing, Android RATs & More The Hacker News
Exploitation of TrueConf Flaw Targets Southeast Asian Governments Exploitation of TrueConf Flaw Targets Southeast Asian Governments The Hacker News
Critical vm2 Node.js Flaw Allows Sandbox Escape and Arbitrary Code Execution Critical vm2 Node.js Flaw Allows Sandbox Escape and Arbitrary Code Execution The Hacker News
New Pixnapping Android Flaw Lets Rogue Apps Steal 2FA Codes Without Permissions New Pixnapping Android Flaw Lets Rogue Apps Steal 2FA Codes Without Permissions The Hacker News
Thermo Fisher Fixes DNA Software Vulnerability Thermo Fisher Fixes DNA Software Vulnerability The Hacker News
Qilin Ransomware Exploits PAN-OS Vulnerability for Access Qilin Ransomware Exploits PAN-OS Vulnerability for Access The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cyberattack Disrupts Ceva Logistics in Europe
  • Adobe Fixes Critical ColdFusion and Campaign Classic Vulnerabilities
  • Phishing Campaign Exploits Google Branding with Fake Email
  • Intel and AMD Address Over 80 Security Flaws
  • Microsoft Defender Patch Bypass: New Zero-Day Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cyberattack Disrupts Ceva Logistics in Europe
  • Adobe Fixes Critical ColdFusion and Campaign Classic Vulnerabilities
  • Phishing Campaign Exploits Google Branding with Fake Email
  • Intel and AMD Address Over 80 Security Flaws
  • Microsoft Defender Patch Bypass: New Zero-Day Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark