A study by researchers at Nanyang Technological University in Singapore reveals widespread security vulnerabilities affecting 4G and 5G core networks that could lead to denial-of-service attacks and session hijacking This article explores vulnerabilities lte 5g. . The findings have been published as a paper titled "Understanding Implicit Trust Errors in Core Carrier Networks through Multi-Agent Flaw Discovery and Analysis."
The research has identified dozens of vulnerabilities in LTE/5G signaling interfaces, including Open5GS and OpenAirInterface implementations, as well as five 5G variants (Open5GS, free5GC, OpenAirInterface, SD-Core, and eUPF) across two core signaling protocols: GTP-C and PFCP. Although traditional cellular networks have traditionally isolated physical interfaces to ensure internal trust, the shift towards cloud-native deployments has made these systems more vulnerable to attacks that could reach previously protected areas.
The research team discovered a pattern of blind trust among CN components, coupled with interface weaknesses, allowing an external actor to exploit these vulnerabilities for malicious activities such as DoS attacks and session hijacking when accessible over the internet. An LLM-driven approach generates proof-of-concept (PoC) exploits for identified iTrues, refining them iteratively by executing them against CN implementations and analyzing results. In a hypothetical DoS attack scenario against Open5GS LTE, an attacker can send GTPv2-C messages to exploit a vulnerability during parsing of GTPv2-C Create Session Request messages, leading to the crash of the Serving Gateway Control plane (SGW-C).











