Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-31 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false

Researchers Report 84 Flaws in 4G and 5G Cores, Including Session Hijacking

Summary

NTU Singapore researchers disclosed 84 vulnerabilities across signalling interfaces (GTP-C and PFCP) in LTE/5G core implementations โ€” Open5GS, free5GC, OpenAirInterface, SD-Core, and eUPF. Exploitation could trigger denial of service or session hijacking, allowing attackers to seize control of a user's network session.

Key Details

  • Date: 2026-07-31
  • Source: The Hacker News
  • Reliability: Tier 2/4 โ€” Established cyber journalism
  • Researcher: NTU Singapore
  • Affected Interfaces: GTP-C and PFCP signalling interfaces
  • Affected Implementations: Open5GS, free5GC, OpenAirInterface, SD-Core, eUPF
  • Impact: Denial of service (DoS) and session hijacking

Significance

These vulnerabilities carry direct impact for Australian mobile carriers (Telstra, Optus, TPG) and government agencies deploying 5G infrastructure under the SOCI Act, as well as NZ carriers (Spark, 2degrees, One NZ). The affected implementations (Open5GS, free5GC, SD-Core) are widely used in telecom infrastructure.

Sources