Researchers from Nanyang Technological University uncovered a widespread class of implicit trust errors in 4G and 5G core networks that can lead to denial-of-service and session hijacking attacks. Their study found 84 previously unknown vulnerabilities across open-source and commercial LTE/5G core implementations, including issues in Open5GS, free5GC, OpenAirInterface, SD-Core, eUPF, and XproUPF. #Open5GS #free5GC #OpenAirInterface #SDCore #eUPF #XproUPF #NanyangTechnologicalUniversity
Keypoints
- Dozens of flaws were found in LTE/5G core signaling interfaces using GTP-C and PFCP.
- The root cause is implicit trust between core network components.
- Cloud-native deployments expand exposure of internal interfaces to attackers.
- iFinder used LLM-assisted analysis to discover and validate new vulnerabilities.
- Some flaws enable DoS and session hijacking, including traffic redirection in UPF.
Read More: https://thehackernews.com/2026/07/researchers-report-84-flaws-in-4g-and.html