Using our multi-agent system iFinder, we discover 84 vulnerabilities in the signaling interfaces of LTE/5G core networks, each of which can result in a persistent denial of service that crashes core network functions, and some of which allow a remote attacker to hijack subscriber sessions. Our research covers two LTE implementations (Open5GS, OpenAirInterface) and five 5G implementations (Open5GS, free5GC, OpenAirInterface, SD-Core, eUPF) across the two core signaling protocols GTP-C and PFCP; we find vulnerabilities in every implementation, 81 of which have already been assigned CVEs.
Our research finds these vulnerabilities share a single recurring root cause, implicit trust between core network functions, and are present in widely used open-source LTE/5G cores that back research testbeds and commercial deployments alike.