Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw 25%

By Ravie Lakshmanan19%

7/31/2026, 4:55:00 AM

BS Summary: This article contains 18 faulty reasoning types, including Unattributed Quote, Pessimism Bias, and Framing Effect, with Negativity Bias as the most egregious example at 25.2% saturation with 247 hits. Analysis detected 1,464 faulty-reasoning hits from 981 analyzed words, generating a BS Score of 31.6% and a BS Rank of 25% (20,258 of 26,768 articles). This article is better (less manipulative) than 75.70% of the article peer group.

An academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user's network session. 
The findings have been released by a group of researchers from Singapore's Nanyang Technological University in a paper titled "Understanding Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and Analysis." 
The study has uncovered dozens of vulnerabilities in the signaling interfaces of LTE/5G core networks, and specifically covers two LTE implementations (Open5GS and OpenAirInterface) and five 5G implementations (Open5GS, free5GC, OpenAirInterface, SD-Core, and eUPF) across two core signaling protocols, GPRS Tunnelling Protocol Control Plane (GTP-C) and Packet Forwarding Control Protocol (PFCP). 
"Our research finds these vulnerabilities share a single recurring root cause, implicit trust between core network functions, and are present in widely used open-source LTE/5G cores that back research testbeds and commercial deployments alike," the researchers said. 
While cellular core networks (CNs) have historically incorporated physical isolation as a means to ensure interfaces between core network functions operate within a trust zone, the transition to cloud-native deployments has made the trust model "fragile" and expanded the attack surface, allowing adversaries to potentially reach previously internal interfaces. 
The researchers said they found a pattern of blind trust among CN components, which, coupled with weaknesses in those interfaces, can be exploited by an external actor for conducting malicious activities, including DoS and session hijacking, when they become reachable over the internet. 
These errors have been codenamed implicit trust errors (iTrue). 
To better detect such iTrues and understand their consequences, the study involved the development of a large language model (LLM)-assisted multi-agent system dubbed iFinder that performs a series of tasks: summarize known flaws, categorize them into detection patterns, and use them as a foundation to discover new iTrues in CN implementations. 
Some of the identified weaknesses relate to a lack of due diligence in validating message format, message semantics, and resource availability, with the CN components opting to blindly act on messages received from internal peers. 
In the next phase, hallucinations and false positives are weeded out using a "novel code-specification cross-checking technique," following which an LLM-driven approach is used to generate proof-of-concept (PoC) exploits for potential iTrues and refine them iteratively by executing them against CN implementations and analyzing the results. 
The elimination of false positives, the researchers said, involves mapping an iTrue candidate to the protocol procedure it implements and checking whether the necessary validation and resource checks are actually enforced in the codebase. 
Running the agent against the aforementioned seven 4G and 5G open-source CN implementations has uncovered 84 previously unknown vulnerabilities, out of which 83 have already been confirmed and 81 have been assigned CVE identifiers. 
Some of the iTrue flaws in 5G systems are said to have been inherited from their 4G counterparts, indicating how security risks can jump generations and how a failure to adapt legacy to modern deployments can bring forth new concerns not previously accounted for. 
That said, successful attacks based on the DoS and session hijacking iTrue flaws assumes the adversary can obtain the IP address of core network components, such as from public documentation, passive enumeration, or active scanning, as well as have access to internal core network interfaces and send arbitrary PFCP and GTP-C messages in violation of the trust model by exploiting misconfigurations in cloud deployment. 
This attacker could be remote (i.e., located outside of the cellular core network) or a malicious User Equipment (UE) used to connect to a mobile network, the latter of which entails injecting carefully crafted payloads into the uplink data stream. 
"By exploiting protocol tunnelling and network boundary bridging, the attacker smuggles crafted PFCP or GTP-C messages inside GTP-U messages so that, absent strict boundary enforcement, they cross the boundary and are delivered to and parsed by core-network components," the researchers said. 
In a hypothetical DoS attack scenario against Open5GS LTE, an attacker can send GTPv2-C messages to trigger the vulnerability when parsing GTPv2-C Create Session Request messages, causing the Serving Gateway Control plane (SGW-C) to crash. 
As for session hijacking, an internet adversary can perform the following sequence of actions - 
* The attacker sends a PFCP Association Setup Request to the User Plane Function (UPF). 
* The victim UE initiates an "attach," triggering the SMF to send a PFCP Session Establishment Request to the UPF. 
* The attacker then issues a PFCP Session Modification Request that reuses the victim's Packet Detection Rule (PDR) ID with a lower Precedence value (higher priority) and binds it to a malicious Forwarding Action Rule (FAR). 
* The UPF admits the duplicate PDR and sorts PDRs by precedence, placing the malicious rule ahead of the legitimate one. 
* During packet processing, the UPF matches the malicious PDR first, and establishes a new forwarding tunnel between UPF and the attacker. 
* The victim's uplink traffic is forwarded to the attacker rather than to the internet. 
"The attacker could be remote (i.e., located outside of the cellular core network) or a malicious User Equipment (UE) used to connect to a mobile network, the latter of which entails injecting carefully crafted payloads into the uplink data stream." 
The session hijacking vulnerability has been discovered on two real-world commercial 5G core networks. 
One vendor, Dotouch, has since addressed the defect in XproUPF (CVE-2026-8233, CVSS score: 4.6). 
The second commercial 5GC vendor, an unnamed major 5G carrier, is still in the remediation process. 
"The continually increasing number of vulnerabilities demonstrates that this is not a small collection of isolated implementation bugs, but a broader and ongoing security problem that requires urgent attention from vendors and network operators," Ziyu Lin, one of the authors of the study, said in a statement shared with The Hacker News. 
Article reasoning-pattern comparisonThis article: 7.8%Ravie Lakshmanan: 1.3%The Hacker News: 1.7%Confirmation Bias7.8%This article: 4.8%Ravie Lakshmanan: 1.0%The Hacker News: 1.0%Anchoring Bias4.8%This article: 6.6%Ravie Lakshmanan: 2.0%The Hacker News: 2.8%Availability Heuristic6.6%This article: 4.9%Ravie Lakshmanan: 1.3%The Hacker News: 1.2%Representativeness Heuristic4.9%This article: 0.0%Ravie Lakshmanan: 0.5%The Hacker News: 0.5%Hindsight Bias0.0%This article: 8.5%Ravie Lakshmanan: 1.9%The Hacker News: 2.2%Overconfidence Bias8.5%This article: 11.5%Ravie Lakshmanan: 2.0%The Hacker News: 2.2%Framing Effect11.5%This article: 0.0%Ravie Lakshmanan: 0.5%The Hacker News: 0.8%Loss Aversion0.0%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.5%Status Quo Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Sunk Cost Effect0.0%This article: 0.0%Ravie Lakshmanan: 1.3%The Hacker News: 1.1%Optimism Bias0.0%This article: 15.6%Ravie Lakshmanan: 1.1%The Hacker News: 1.3%Pessimism Bias15.6%This article: 25.2%Ravie Lakshmanan: 5.6%The Hacker News: 5.5%Negativity Bias25.2%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 0.7%Self-Serving Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 0.3%Fundamental Attribution Error0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Actor-Observer Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%In-Group Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.8%The Hacker News: 0.3%Out-Group Homogeneity Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.3%The Hacker News: 0.4%Halo Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 1.5%Ravie Lakshmanan: 1.5%The Hacker News: 1.3%Recency Bias1.5%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.2%Primacy Effect0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Blind-Spot Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Ad Hominem0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Straw Man0.0%This article: 8.6%Ravie Lakshmanan: 3.1%The Hacker News: 3.2%Appeal to Authority8.6%This article: 0.0%Ravie Lakshmanan: 0.5%The Hacker News: 1.3%False Dilemma0.0%This article: 4.2%Ravie Lakshmanan: 0.4%The Hacker News: 0.5%Slippery Slope4.2%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Circular Reasoning0.0%This article: 10.2%Ravie Lakshmanan: 3.2%The Hacker News: 3.6%Hasty Generalization10.2%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Red Herring0.0%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.2%Bandwagon0.0%This article: 0.0%Ravie Lakshmanan: 0.9%The Hacker News: 0.9%Appeal to Emotion0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.4%Begging the Question0.0%This article: 5.0%Ravie Lakshmanan: 1.6%The Hacker News: 1.6%Post Hoc (False Cause)5.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Tu Quoque0.0%This article: 0.0%Ravie Lakshmanan: 0.5%The Hacker News: 0.5%Burden of Proof0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Appeal to Nature0.0%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.3%Composition/Division0.0%This article: 0.0%Ravie Lakshmanan: 0.2%The Hacker News: 0.8%Anecdotal0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%No True Scotsman0.0%This article: 4.5%Ravie Lakshmanan: 2.4%The Hacker News: 1.8%Ambiguity (Equivocation)4.5%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.1%Special Pleading0.0%This article: 0.0%Ravie Lakshmanan: 0.1%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 19.9%Ravie Lakshmanan: 2.4%The Hacker News: 1.2%Unattributed Quote19.9%This article: 3.8%Ravie Lakshmanan: 1.7%The Hacker News: 0.8%Quote-first Misdirection3.8%This article: 1.4%Ravie Lakshmanan: 1.8%The Hacker News: 1.9%Biased Writer Voice1.4%This article: 5.3%Ravie Lakshmanan: 1.5%The Hacker News: 3.3%Indoctrination5.3%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 0.0%Ravie Lakshmanan: 0.4%The Hacker News: 2.5%Attempt to Sell a Product or S…0.0%

981 words analyzed.

Speakers

1speaker5.3%attributed speech929writer words
Selected voice

Ziyu Lin

100%flagged-word coverage
52 attributed words100% of attributed speech68% writer coverage
0%50.0%100.0%Indoctrination+100.0 ptsWriter: 0.0%Ziyu Lin: 100.0%100.0%Unattributed Quote-21.0 ptsWriter: 21.0%Ziyu Lin: 0.0%0.0%Quote-first Misdirection-4.0 ptsWriter: 4.0%Ziyu Lin: 0.0%0.0%Biased Writer Voice-1.5 ptsWriter: 1.5%Ziyu Lin: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.