84 Vulnerabilities in 4G and 5G Core: Implicit Trust Between Signaling Functions Betrays Networks
Researchers uncovered 84 vulnerabilities in 4G and 5G core networks caused by implicit trust between signaling, enabling DoS and session hijacking.
Illustrative image generated with AI
The Discovery: A Single Design Flaw Spawns Dozens of Vulnerabilities
A research group from Singapore’s Nanyang Technological University has uncovered 84 vulnerabilities affecting fourth- and fifth-generation core networks. The flaws, disclosed on July 31, 2026, share a common root: the “implicit trust” (iTrue) that network functions grant one another when exchanging signaling messages. In practice, the affected modules accept and process data without any formal, semantic, or resource-consistency validation.
The team reproduced the attacks in several open‑source implementations: Open5GS, OpenAirInterface (both LTE and 5G versions), free5GC, SD‑Core, and eUPF. While some of these stacks power academic testbeds, they are also used in light commercial environments. CVE identifiers have already been assigned for 81 of the 84 vulnerabilities, underlining the cross‑cutting relevance of the gaps. The affected protocols are GTPv2‑C on the control plane and PFCP (Packet Forwarding Control Protocol), which governs the user plane.
iFinder, the AI‑Powered Automatic Vulnerability Hunter
Rather than auditing codebases manually, the researchers built iFinder, a multi‑agent system that leverages large language models (LLMs) to automate the discovery of iTrue‑related flaws. The system parses specifications, implementations, and signaling flows, automatically identifying the points where absent checks allow malformed or unauthorized messages to get through. The method precisely mapped the contexts in which implicit trust becomes an exploitable vulnerability.
Two Attack Scenarios: From Control‑Plane Crash to Session Hijacking
The impact is high. The researchers demonstrated two main attack classes, both rated as medium complexity for an adversary able to reach internal interfaces (a goal made easier by misconfigured cloud setups or malicious user devices already attached to the network).
- Denial of Service: Sending malformed GTPv2‑C messages to the Serving Gateway Control Plane (SGW‑C) crashes it, disrupting session management and rendering services unavailable.
- Session Hijacking: An attacker can inject a forged PFCP Session Modification Request. The User Plane Function (UPF) interprets it as legitimate and applies malicious forwarding rules with higher priority. The victim’s uplink traffic is then diverted to the attacker, enabling full interception.
In several cases, vulnerabilities inherited from 4G propagate directly to 5G networks because the architecture reuses portions of the core and the same signaling principles.
No Immediate Patch: An Architectural Rethink Is Needed
The paper does not provide specific fixes. The recommended structural mitigation is to eliminate the concept of implicit trust between Network Functions altogether, by enforcing mandatory checks on format, semantics, and resource availability for every incoming message. This should be accompanied by tighter core‑network segmentation and hardening of cloud configurations—two deterrents against unauthorized access to signaling interfaces.
For operators and developers of open‑source implementations, the message is clear: GTP and PFCP message validation must be redesigned from the ground up. While waiting for official updates, those running networks based on Open5GS, free5GC, or other affected stacks can reduce exposure by strengthening network policies, restricting reachability of internal interfaces, and actively monitoring signaling flows.
Sources
This article is an original reworking based on the sources below.




