4G/5G core implicit trust errors (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
Researchers disclosed 84 implicit-trust flaws in 4G/5G core networks, exposing Open5GS, OpenAirInterface, free5GC, SD-Core, and eUPF to DoS and session hijacking risk through GTP-C and PFCP.
Timeline
-
31.07.2026 14:55 2 articles · 5h ago
Researchers disclose 84 implicit-trust flaws in 4G and 5G core networks
Initial DisclosureSingapore's Nanyang Technological University disclosed a widespread class of implicit trust errors (iTrue) in 4G and 5G core networks, saying its iFinder framework uncovered 84 previously unknown vulnerabilities across Open5GS, OpenAirInterface, free5GC, SD-Core, and eUPF. The flaws affect GTP-C and PFCP signaling paths and can enable denial-of-service or session hijacking; 83 findings were confirmed and 81 received CVE identifiers. Dotouch has already fixed a related XproUPF defect as CVE-2026-8233, while an unnamed major 5G carrier remains in remediation.
Show sources
- Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw — thehackernews.com — 31.07.2026 14:55
- Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw — thehackernews.com — 31.07.2026 14:55