HackMyIP
← Back to News
2026-07-31 The Hacker News

84 Flaws Found in 4G/5G Cores Enable Session Hijacking Attacks

VulnerabilityAI Security

Researchers from Singapore's Nanyang Technological University have uncovered 84 security flaws across 4G and 5G core network implementations, including a critical vulnerability that could allow attackers to hijack user sessions. The study, published in a paper titled "Understanding Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and Analysis," identifies a recurring root cause dubbed "implicit trust errors" (iTrue) — a pattern of blind trust between core network functions that has become dangerous as carriers migrate to cloud-native architectures. The flaws were discovered in two LTE implementations (Open5GS and OpenAirInterface) and five 5G implementations (Open5GS, free5GC, OpenAirInterface, SD-Core, and eUPF), spanning two core signaling protocols: GPRS Tunnelling Protocol Control Plane (GTP-C) and Packet Forwarding Control Protocol (PFCP).

The vulnerabilities stem from core network components failing to adequately validate message formats, message semantics, and resource availability from internal peers. Historically, cellular core networks relied on physical isolation to enforce trust between functions, but the shift to cloud-native deployments has shattered that trust boundary. When previously internal signaling interfaces become reachable over the internet, attackers can exploit these implicit trust gaps to launch denial-of-service attacks or seize control of active user sessions. Researchers warn that these flaws aren't limited to academic testbeds — they affect open-source LTE/5G cores used in commercial deployments as well, making the attack surface far broader than initially assumed.

To systematically identify these flaws at scale, the team built iFinder, an LLM-assisted multi-agent system that summarizes known flaws, categorizes them into detection patterns, and uses those patterns as a foundation to discover new iTrues. False positives are filtered through a code-specification cross-checking technique, after which an LLM-driven pipeline generates proof-of-concept exploits and iteratively refines them by executing against live CN implementations. This AI-augmented approach demonstrates how large language models are reshaping offensive security research — both for defenders and potential adversaries. Organizations running cellular core infrastructure should audit their deployments immediately and verify that signaling interfaces are not inadvertently exposed. Operators concerned about network exposure can use a port scanner to audit public-facing attack surfaces, or a VPN/proxy detector to confirm whether carrier traffic is being routed through unexpected intermediaries.

The disclosure underscores a growing tension in telecom security: protocols designed under an assumption of internal trust are now operating in hostile, internet-connected environments. With 84 confirmed flaws across major open-source LTE and 5G stacks, the research community and carriers alike face a substantial remediation effort. Network operators, security teams, and end users should stay vigilant — session hijacking at the carrier level can bypass even strong endpoint protections. For ongoing monitoring of exposed infrastructure, security professionals can run a WHOIS lookup on suspicious signaling endpoints and review their broader posture using the platform's full suite of diagnostic tools.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →