AI Agents Uncover 84 Security Flaws in 4G and 5G Network Cores
Researchers used multi-agent AI to expose vulnerabilities in widely deployed telecom infrastructure, including a traffic hijacking flaw validated on commercial networks.
AI-powered discovery challenges telecom security assumptions
Researchers at Nanyang Technological University have used artificial intelligence agents to identify 84 previously unknown security vulnerabilities in widely deployed 4G and 5G network core implementations, fundamentally challenging the telecom industry's assumption that internal mobile core networks are inherently secure.
The research team deployed iFinder, a multi-agent large language model system, to scan seven different 4G and 5G core implementations. Of the 84 vulnerabilities discovered, 83 were confirmed and 81 received Common Vulnerabilities and Exposures (CVE) identifiers, according to details first reported by Fierce Wireless.
Why it matters
This research demonstrates that adversaries can now use AI to discover telecom vulnerabilities at a pace that outstrips traditional security auditing and patch cycles. More fundamentally, it exposes a dangerous architectural assumption: that "internal" network interfaces are protected by their position inside the network perimeter. In cloud-native 5G deployments, misconfigured clusters, shared infrastructure, or compromised workloads can expose interfaces that were never designed to face hostile traffic.
Traffic hijacking validated on commercial networks
The most significant finding is CVE-2026-8233, a PFCP (Packet Forwarding Control Protocol) session hijacking vulnerability that could allow an attacker with access to a User Plane Function's internal interface to redirect a subscriber's uplink traffic. The research team validated this attack against two commercial 5G core deployments, elevating the threat beyond theoretical open-source concerns.
Interfaces including N4/PFCP and S11/S5/GTP-C, traditionally considered protected because they operate "internally," now require the same authentication, segmentation, and message validation applied to internet-facing systems.
Concentration in user plane components
The majority of discovered vulnerabilities were concentrated in PFCP/User Plane Function and GTP-C/Serving Gateway code. This concentration suggests that operators should prioritize patch verification and exposure audits for these specific components, while vendors need to treat session-state validation, identifier checks, and resource limits as urgent engineering priorities.
Beyond patching: architectural redesign needed
The findings point to specification-level and architecture-level trust assumptions embedded in telecom standards, not merely implementation errors. The researchers argue that vendors must redesign for zero-trust principles rather than applying reactive fixes. This includes baking in mutual authentication, strict input validation, state-invariant checks, and bounded resource allocation across internal signaling paths.
The research underscores a new security reality: if academic researchers can deploy AI agents to discover and exploit telecom flaws at scale, adversaries possess the same capability. Telecom operators and equipment vendors face an accelerated vulnerability discovery timeline that current security processes may not be equipped to handle.
The findings were first reported by Fierce Wireless, based on research from Nanyang Technological University.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call