Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Unveiling the Hidden Vulnerabilities: An In-Depth Analysis of 4G and 5G Cores' Security Weaknesses




The recent study by researchers from Singapore's Nanyang Technological University has identified 84 flaws in 4G and 5G cores, including a session hijacking vulnerability. These vulnerabilities, dubbed "implicit trust errors," can trigger denial-of-service attacks and allow an attacker to seize control of a user's network session. The study highlights the need for vendors and network operators to prioritize security measures and address these vulnerabilities promptly.

  • The researchers identified 84 flaws in 4G and 5G cores, dubbed "implicit trust errors," which can trigger denial-of-service attacks and allow attackers to seize control of a user's network session.
  • The study highlights the need for vendors and network operators to prioritize security measures and address these vulnerabilities promptly.
  • The implicit trust errors were found in the signaling interfaces of LTE/5G core networks, including weaknesses in GPRS Tunnelling Protocol Control Plane (GTP-C) and Packet Forwarding Control Protocol (PFCP).
  • A session hijacking vulnerability was discovered on two real-world commercial 5G core networks, with one vendor already addressing the issue.
  • The researchers developed an LLM-assisted multi-agent system called "iFinder" to detect such vulnerabilities and understand their consequences.



  • The world of telecommunications has long been touted as a bastion of technological advancements, where innovation and progress are the cornerstones of success. However, with great power comes great responsibility, and the recent disclosure of 84 flaws in 4G and 5G cores serves as a poignant reminder of the importance of vigilance when it comes to security. In this article, we will delve into the details of these vulnerabilities, their potential impact on users, and what steps can be taken to mitigate them.

    In a groundbreaking study published recently, researchers from Singapore's Nanyang Technological University have identified a "widespread class" of security vulnerabilities impacting 4G and 5G core networks. These flaws, which have been dubbed "implicit trust errors" (iTrue), can trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user's network session.

    The researchers' findings have shed light on the previously unexplored realm of implicit trust between core network functions, highlighting how this trust model has become "fragile" with the transition to cloud-native deployments. This shift has expanded the attack surface, making it easier for adversaries to reach previously internal interfaces and exploit these vulnerabilities.

    One of the most significant implications of this study is the discovery of a pattern of blind trust among CN components, which can be exploited by an external actor for conducting malicious activities, including DoS and session hijacking. The researchers have developed a large language model (LLM)-assisted multi-agent system dubbed "iFinder" to better detect such iTrues and understand their consequences.

    The iFinder framework involves the development of a novel code-specification cross-checking technique, followed by an LLM-driven approach to generate proof-of-concept (PoC) exploits for potential iTrues. The elimination of false positives is achieved by mapping an iTrue candidate to the protocol procedure it implements and checking whether the necessary validation and resource checks are actually enforced in the codebase.

    The researchers' investigation has uncovered 84 previously unknown vulnerabilities, out of which 83 have already been confirmed and 81 have been assigned CVE identifiers. Some of these flaws relate to a lack of due diligence in validating message format, message semantics, and resource availability, with the CN components opting to blindly act on messages received from internal peers.

    The study has also identified weaknesses in the signaling interfaces of LTE/5G core networks, specifically covering two LTE implementations (Open5GS and OpenAirInterface) and five 5G implementations (Open5GS, free5GC, OpenAirInterface, SD-Core, and eUPF) across two core signaling protocols, GPRS Tunnelling Protocol Control Plane (GTP-C) and Packet Forwarding Control Protocol (PFCP).

    One of the most concerning examples of a session hijacking vulnerability has been discovered on two real-world commercial 5G core networks. In one instance, a vendor named Dotouch has addressed the defect in XproUPF (CVE-2026-8233), while a second major 5G carrier is still in the remediation process.

    The researchers' findings have far-reaching implications for the cybersecurity landscape, highlighting the need for vendors and network operators to prioritize security measures and address these vulnerabilities promptly. As Ziyu Lin, one of the authors of the study, noted, "The continually increasing number of vulnerabilities demonstrates that this is not a small collection of isolated implementation bugs, but a broader and ongoing security problem that requires urgent attention from vendors and network operators."

    In conclusion, the recent disclosure of 84 flaws in 4G and 5G cores serves as a stark reminder of the importance of prioritizing security measures. As we move forward into an increasingly complex technological landscape, it is essential that we adopt a proactive approach to identifying and addressing vulnerabilities such as these.



    The recent study by researchers from Singapore's Nanyang Technological University has identified 84 flaws in 4G and 5G cores, including a session hijacking vulnerability. These vulnerabilities, dubbed "implicit trust errors," can trigger denial-of-service attacks and allow an attacker to seize control of a user's network session. The study highlights the need for vendors and network operators to prioritize security measures and address these vulnerabilities promptly.




    Related Information:
  • https://www.ethicalhackingnews.com/articles/Unveiling-the-Hidden-Vulnerabilities-An-In-Depth-Analysis-of-4G-and-5G-Cores-Security-Weaknesses-ehn.shtml

  • https://thehackernews.com/2026/07/researchers-report-84-flaws-in-4g-and.html


  • Published: Fri Jul 31 11:29:29 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us