Affected Systems
4G and 5G core network implementations: Open5GS (LTE/5G), free5GC, OpenAirInterface (LTE/5G), SD-Core, and eUPF. Vulnerabilities affect GTP-C and PFCP signaling protocols. 83 of 84 flaws confirmed, 81 assigned CVE identifiers. Impacts research testbeds and commercial deployments using these open-source cores.
Exploitation Status
Proof-of-concept exploits generated and validated by researchers. Exploitation requires attacker to obtain IP addresses of core network components and access internal interfaces (via misconfigurations in cloud deployments or malicious User Equipment). No evidence of active exploitation in the wild reported.
Business Impact
Mobile network operators and enterprises running affected 4G/5G core implementations face risk of denial-of-service attacks causing service outages and session hijacking enabling traffic interception. Root cause is implicit trust between core network functions—components blindly accept messages from internal peers without validation. Cloud-native deployments expand attack surface by making previously isolated internal interfaces reachable. Legacy 4G flaws inherited by 5G systems compound risk across generations.
Urgency
🟡 Within a week
Recommended Actions
- Identify if your 4G/5G core uses Open5GS, free5GC, OpenAirInterface, SD-Core, or eUPF and review vendor advisories for the 81 assigned CVE identifiers
- Apply patches for confirmed vulnerabilities in GTP-C and PFCP protocol handling, prioritizing SGW-C, SMF, and UPF components
- Audit cloud deployment configurations to ensure strict network segmentation and prevent external access to internal core network interfaces (GTP-C, PFCP)
- Implement validation controls for message format, semantics, and resource uniqueness between core network functions—specifically PDR ID uniqueness in PFCP Session Modification Requests
- Monitor for anomalous GTP-C and PFCP traffic patterns, including unexpected Association Setup Requests and Session Modification Requests from untrusted sources
---
# Geopolitical Context
Geopolitical Context
The disclosure of 84 vulnerabilities in widely deployed open-source 4G and 5G core network implementations by Nanyang Technological University researchers highlights systemic security challenges in the global transition to cloud-native telecommunications infrastructure. The findings reveal a "widespread class" of implicit trust errors (iTrues) affecting critical signaling protocols (GTP-C and PFCP) across multiple implementations including Open5GS, free5GC, OpenAirInterface, SD-Core, and eUPF. These platforms underpin both research testbeds and commercial deployments globally, indicating that the vulnerabilities have broad reach across national telecommunications ecosystems. The shift from physically isolated legacy networks to cloud-native 5G architectures has expanded the attack surface by exposing previously internal interfaces, creating new vectors for denial-of-service and session hijacking attacks. The research demonstrates that security flaws can propagate across technology generations, with 5G systems inheriting vulnerabilities from 4G predecessors. This represents a strategic concern for states investing heavily in 5G rollouts as critical infrastructure, particularly given the protocol-level nature of the flaws rather than implementation-specific bugs.
State Actor Alignment
No state actor attribution or alignment is indicated in this disclosure. The research originates from an academic institution in Singapore and focuses on technical vulnerabilities in open-source telecommunications software rather than threat actor activity. However, the nature of the vulnerabilities—enabling DoS attacks and session hijacking against core network functions—presents capabilities that would be of strategic interest to signals intelligence agencies and offensive cyber programs globally. The flaws affect infrastructure that falls under critical national infrastructure protection frameworks in most jurisdictions, and their disclosure will likely prompt regulatory review by telecommunications authorities in the United States (FCC, CISA), European Union (ENISA, NIS2 Directive scope), and other regions with 5G security oversight mechanisms. The 81 assigned CVE identifiers indicate coordinated vulnerability disclosure processes were followed, suggesting engagement with affected vendors and potentially national cybersecurity coordination centers.
Business Impacty pro region
The vulnerabilities have global implications given the widespread deployment of the affected open-source implementations. European operators and research institutions that have adopted Open5GS, free5GC, or OpenAirInterface in testbeds or production environments face potential exposure, particularly in markets where open-source alternatives to proprietary vendor equipment (Ericsson, Nokia, Huawei) have gained traction. The findings may influence ongoing European telecommunications security policy debates, including supply chain diversification efforts under the EU 5G Toolbox and Open RAN initiatives. For the Indo-Pacific region, Singapore's research leadership in identifying these flaws reinforces the city-state's positioning as a regional cybersecurity hub and may inform ASEAN telecommunications security coordination. The disclosure could complicate 5G rollout timelines in emerging markets where cost-effective open-source solutions have been considered as alternatives to expensive proprietary systems. In the United States, where Open RAN and software-defined networking are promoted as strategic alternatives to Chinese telecommunications equipment, these findings may prompt increased scrutiny of open-source 5G stack security and potentially influence funding priorities under programs like the NTIA's Public Wireless Supply Chain Innovation Fund.
Forecast
If exploitation of these vulnerabilities is observed in the wild, it is likely to manifest first as denial-of-service incidents against telecommunications providers using affected open-source implementations in production or hybrid environments. Session hijacking attacks, while more complex to execute, could enable sophisticated threat actors to intercept mobile user traffic if they can achieve the prerequisite conditions (access to internal core network interfaces through cloud misconfigurations or network boundary exploitation). Vendors and operators are likely to prioritize patching efforts given the 81 assigned CVEs, though deployment timelines will vary significantly between research testbeds and commercial networks. Regulatory bodies in major markets may issue guidance or directives requiring telecommunications operators to assess exposure and implement mitigations, particularly for networks supporting critical infrastructure or government communications. If proof-of-concept exploits become publicly available or are incorporated into offensive toolkits, the window for opportunistic exploitation will narrow, potentially accelerating patch adoption. The research methodology using LLM-assisted vulnerability discovery may also prompt broader discussion within the telecommunications security community about the adequacy of current secure development practices for cloud-native network functions, potentially influencing future 3GPP security specifications and vendor security testing requirements.
