Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
84 Security Flaws Uncovered in 4G and 5G Networks

84 Security Flaws Uncovered in 4G and 5G Networks

Posted on July 31, 2026 By CWS

A recent study has identified 84 security vulnerabilities in the core networks of 4G and 5G technologies. These flaws, if exploited, can facilitate denial-of-service (DoS) attacks and session hijacking, where an attacker seizes control of a user’s network session. The research, conducted by Nanyang Technological University in Singapore, highlights critical issues within the signaling interfaces of both LTE and 5G core networks.

Key Findings of the Study

The researchers focused on various implementations of LTE and 5G, including Open5GS, OpenAirInterface, and others. They discovered recurring vulnerabilities rooted in “implicit trust” between core network functions. Historically, these networks relied on physical isolation to secure internal interfaces. However, the shift to cloud-native deployments has weakened this trust model, increasing the attack surface and making these vulnerabilities more accessible to attackers.

The study termed these vulnerabilities as “implicit trust errors” (iTrue) and developed a multi-agent system called iFinder to identify these flaws. This system categorizes known vulnerabilities and searches for new ones using a large language model (LLM). It also helps in creating proof-of-concept exploits to test and refine the understanding of these flaws.

Implications for Network Security

The vulnerabilities were found across seven open-source LTE/5G core network implementations, with 83 confirmed and 81 assigned CVE identifiers. The study also revealed that some of these flaws in 5G systems were inherited from older 4G technologies, underscoring the risks posed by legacy systems not adapting to modern deployments.

One example of a session hijacking attack involves exploiting duplicate Packet Detection Rule (PDR) IDs within PFCP Session Modification Request messages. This can lead to a user’s uplink traffic being rerouted to an attacker instead of its intended destination, posing significant security risks.

Vendor and Network Operator Responses

Addressing these vulnerabilities is crucial for vendors and network operators. One vendor, Dotouch, has already tackled a session hijacking flaw (CVE-2026-8233), while another unnamed major 5G carrier is still working on remediation. The study’s authors stress the urgency of addressing these issues, as the growing number of vulnerabilities signifies a broad security challenge rather than isolated bugs.

As these flaws expose critical weaknesses in telecommunications infrastructure, immediate action from vendors and network operators is imperative to safeguard against potential exploits.

The Hacker News Tags:4G, 5G, cloud-native, core networks, Cybersecurity, DoS attacks, GTP-C, LTE, network operators, network security, PFCP, protocol tunneling, security vulnerabilities, session hijacking, Telecommunications

Post navigation

Previous Post: FBI Warns of North Korean IT Workers Using False Identities
Next Post: AI Powers Google Chrome Security with 1,072 Fixes

Related Posts

GlassWorm Returns with 24 Malicious Extensions Impersonating Popular Developer Tools GlassWorm Returns with 24 Malicious Extensions Impersonating Popular Developer Tools The Hacker News
Cybersecurity Threats: Game Cheat Spyware and More Cybersecurity Threats: Game Cheat Spyware and More The Hacker News
Windows Vulnerabilities: BitLocker Bypass and CTFMON Exploit Windows Vulnerabilities: BitLocker Bypass and CTFMON Exploit The Hacker News
WhatsApp Introduces Usernames for Enhanced Privacy WhatsApp Introduces Usernames for Enhanced Privacy The Hacker News
WinRAR Vulnerability CVE-2025-6218 Under Active Attack by Multiple Threat Groups WinRAR Vulnerability CVE-2025-6218 Under Active Attack by Multiple Threat Groups The Hacker News
High-Severity Vulnerability Patched in n8n Workflow Platform High-Severity Vulnerability Patched in n8n Workflow Platform The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Powers Google Chrome Security with 1,072 Fixes
  • 84 Security Flaws Uncovered in 4G and 5G Networks
  • FBI Warns of North Korean IT Workers Using False Identities
  • OpenAI’s New Tool and Cybersecurity Updates
  • Security Risks in Budget Android TV Boxes Exposed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Powers Google Chrome Security with 1,072 Fixes
  • 84 Security Flaws Uncovered in 4G and 5G Networks
  • FBI Warns of North Korean IT Workers Using False Identities
  • OpenAI’s New Tool and Cybersecurity Updates
  • Security Risks in Budget Android TV Boxes Exposed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark