Researchers map 84 implicit-trust flaws across 4G and 5G cores

An academic study found dozens of vulnerabilities in open-source 4G and 5G core networks rooted in implicit trust.

CSBadmin
2 Min Read

An academic team from Singapore’s Nanyang Technological University has identified a broad class of security flaws across 4G and 5G core networks that can be abused for denial-of-service attacks and to take over a user’s active network session.

The paper, posted on arXiv, examines two LTE implementations (Open5GS and OpenAirInterface) plus five 5G implementations (Open5GS, free5GC, OpenAirInterface, SD-Core, and eUPF), covering the GTP-C and PFCP signaling protocols. Dozens of vulnerabilities emerged, all traced to one underlying pattern the researchers call implicit trust errors, or iTrue: core network functions blindly trust messages from internal peers.

That trust model worked when physical isolation kept the interfaces between core functions inside a protected zone. Cloud-native deployments have eroded that boundary, the researchers argue, widening the attack surface so adversaries can reach interfaces that were previously internal. Components act on messages without properly checking format, semantics, or resource availability.

To scale the hunt, the team built iFinder, an LLM-assisted multi-agent system that digests known flaws, classifies them into detection patterns, and uses those patterns to discover new instances. The work confirmed a live session hijacking bug on two commercial 5G core networks in production. One vendor, Dotouch, has fixed the flaw in XproUPF (CVE-2026-8233, CVSS 4.6); the second operator, an unnamed major carrier, is still remediating.

Ziyu Lin, one of the study’s authors, argues the findings point to a systemic problem rather than isolated coding mistakes, calling on vendors and operators to treat the rising vulnerability count as an urgent, ongoing concern.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.