NTU's iFinder finds 84 flaws in 5G network software, 23 still unfixed
This digest was compiled by AI from multiple sources — links to the originals are below.

Researchers at Nanyang Technological University used an AI tool called iFinder to uncover 84 previously unreported security flaws in 4G and 5G network software, with 23 still lacking fixes. The most severe flaw allows an attacker to hijack a subscriber's data session and redirect traffic. The findings underscore risks as operators migrate network cores to cloud environments.
The AI Discovery
An AI tool called iFinder, developed at Nanyang Technological University, identified 84 security flaws in 4G and 5G network software. Developers have confirmed 83 of the flaws, and 81 now carry CVE numbers. The tool employs three sequential AI agents that scan code, consult 3GPP standards, and generate exploits. Of 22 previously known bugs, iFinder caught 15, with roughly a quarter of its reports being false positives.
Session Hijack Mechanism
The most critical flaw, CVE-2026-8233, enables a session hijack where an attacker can redirect a subscriber's data traffic. The vulnerability arises because internal network instructions, designed for closed environments, lack proper authentication. An attacker can craft a higher-priority forwarding rule using a victim's existing rule ID, causing the network to deliver the victim's outbound traffic to the attacker. The attack was demonstrated on OpenAirInterface's 5G core and validated on two commercial 5G networks. One vendor has patched the flaw; a major 5G carrier is still working on a fix.
Cloud and SIM Attack Vectors
Network operators increasingly moving cores to cloud environments heighten the risk, as misconfigurations can expose internal interfaces to the public internet. The researchers also demonstrated a secondary attack path using a standard phone with a valid SIM, which hid control messages inside its data tunnel. This method succeeded against five of seven open-source cores tested. The iFinder findings highlight the expanding attack surface as cellular infrastructure modernizes.
What's Next
The researchers plan to release iFinder as an open-source tool to aid telecom security audits. It remains unclear how quickly operators and vendors will apply patches, especially as many network components lack automated update mechanisms.
1 source
NTU's iFinder finds 84 flaws in 5G network software, 23 still unfixed



