{"id":135856,"date":"2026-08-11T09:45:10","date_gmt":"2026-08-11T09:45:10","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/135856\/"},"modified":"2026-08-11T09:45:10","modified_gmt":"2026-08-11T09:45:10","slug":"an-ai-tool-found-84-flaws-in-5g-network-software-and-23-of-them-still-have-no-fix","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/135856\/","title":{"rendered":"An AI tool found 84 flaws in 5G network software and 23 of them still have no fix"},"content":{"rendered":"<p>Researchers at Nanyang Technological University turned a set of <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/08\/05\/ai-agent-deception-in-cyber-tests\/\" rel=\"nofollow noopener\" target=\"_blank\">AI agents<\/a> loose on the software that runs 4G and 5G phone networks, and the agents came back with 84 security flaws nobody had reported before.<\/p>\n<p>Developers have confirmed 83 of them, and 81 now carry CVE numbers. The most serious one lets an attacker take over a subscriber\u2019s data session, so the network delivers that subscriber\u2019s traffic to the attacker instead of to the internet.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/08\/G_core_network_vulnerabilities.webp\" class=\"aligncenter\" alt=\"5G core network vulnerabilities\" title=\"Network\"\/><\/p>\n<p>The hijack works because of a bad assumption. Inside a phone network, one component decides where a subscriber\u2019s data should go and tells another component to move it. Those instructions travel over internal links that were designed back when the whole core sat in a locked room, so the receiving side tends to accept whatever arrives without much checking. An attacker who can reach one of those links sends an instruction that reuses the ID of a forwarding rule already assigned to a real subscriber, flagged as higher priority than the original. Nothing verifies that the ID is unique. The network sorts by priority, picks the attacker\u2019s rule, and starts delivering the victim\u2019s outbound traffic to the attacker.<\/p>\n<p>The attack ran end to end in a lab against OpenAirInterface\u2019s 5G core, which is open source. It was then validated on two commercial 5G core networks, including a reproduction inside a partner vendor\u2019s lab under default settings. One vendor has fixed the problem and CVE-2026-8233 was assigned. The other, a major 5G carrier, is still working on it.<\/p>\n<p>What makes this more than a lab curiosity is where phone networks now live. Operators have been moving their cores into cloud environments, and a misconfiguration there can expose an internal interface to the open internet. The researchers also tested a second route in: an ordinary phone with a valid SIM, hiding network control messages inside the data tunnel that carries its own uplink traffic. That trick worked against five of the seven open-source cores they examined.<\/p>\n<p>The tool that found all this, called iFinder, runs three AI agents in a row. The first reads through the code looking for places where data from an incoming message gets used without being checked. The second consults the 3GPP standards documents to figure out whether the missing check happens earlier in the conversation, which is the most common reason a suspicious-looking line of code turns out to be fine. The third writes a working exploit, runs it against a test network, reads the error logs, and rewrites the exploit until it either works or gives up. The pipeline is useful rather than magic: on a set of 22 previously known bugs, it caught 15, and roughly a quarter of everything it reports is wrong.<\/p>\n<p>The reports have landed unevenly. Of the 83 confirmed flaws, 58 have been patched. Three of the seven projects have shipped nothing at all, which leaves 23 confirmed problems that have CVE numbers and no code change behind them.<\/p>\n<p>\u201cThe split mainly reflects maintainer responsiveness and development capacity. OAI has not responded to our reports, while eUPF acknowledged them but indicated that fixes depend on available development resources. Open5GS, SD-Core, and free5GC engaged actively and addressed the reported issues,\u201d Ziyu Lin, a co-author of the <a href=\"https:\/\/arxiv.org\/pdf\/2607.10315\" target=\"_blank\" rel=\"nofollow noopener\">study<\/a>, told Help Net Security.<\/p>\n<p>A batch of machine-generated reports arriving at once could easily have gone badly with maintainers, and the packaging mattered. \u201cAdditionally, every finding was manually reviewed, reproduced, and accompanied by a working PoC before being reported. This helped maintainers treat the batch as a set of verified security reports rather than unfiltered machine-generated results,\u201d Lin said.<\/p>\n<p>The commercial cores got a lighter touch. iFinder needs source code to work, which rules out a shipped product, so the two commercial networks were tested by replaying exploits built against the open-source versions. Three of those exploits worked: the session hijack on both cores, plus two denial-of-service bugs on one of them, one of which has its own CVE. \u201cDirect analysis would require access to the source code, build environment, and a suitable testbed,\u201d Lin said.<\/p>\n<p>That leaves an open question for anyone running a commercial core. Did the vendors inherit these gaps from shared open-source ancestry, or did three findings just happen to land? \u201cMany commercial 5GCs may incorporate or customize open-source stacks, and both free5GC and OAI have downstream commercial derivatives, so validation gaps in the upstream code can propagate into products that carry the same design assumptions,\u201d Lin said. \u201cThree confirmed cases are a small sample, and we have not audited the commercial cores directly, so we would call this supporting evidence rather than a conclusion. Direct analysis of additional commercial cores would be needed to establish how far the inheritance extends.\u201d<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/04\/divider.gif\" class=\"aligncenter\"\/><\/p>\n<p>Download: <a href=\"https:\/\/helpnet.short.gy\/7EcjJ3\" target=\"_blank\" rel=\"nofollow noopener\">The ultimate guide to network operations management<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"Researchers at Nanyang Technological University turned a set of AI agents loose on the software that runs 4G&hellip;\n","protected":false},"author":2,"featured_media":135857,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[2705,24,405,7537,313,3444,52],"class_list":["post-135856","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-5g","tag-ai","tag-ai-agents","tag-artificial-intelligence-agents","tag-cybersecurity","tag-networking","tag-research"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/135856","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=135856"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/135856\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/135857"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=135856"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=135856"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=135856"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}