CVE Tools

An AI tool found 84 flaws in 5G network software and 23 of them still have no fix

Help Net SecurityBy Mirko Zorz

PoC publicOpenAirInterface5G core

Our summary

Researchers at Nanyang Technological University employed an AI agent pipeline called iFinder to audit 4G and 5G network infrastructure, identifying 84 previously undisclosed security vulnerabilities. Of these, developers have confirmed 83, with 81 assigned CVE numbers, though 23 confirmed issues currently lack a patch.

The most severe finding enables an attacker to hijack a subscriber's data session by injecting a fraudulent forwarding rule with higher priority into internal network links. This flaw was successfully exploited end-to-end against the open-source OpenAirInterface 5G core and subsequently validated on two commercial 5G core networks, including one major carrier. While one vendor issued a fix designated as CVE-2026-8233, the other remains in remediation. The study highlights risks associated with migrating core functions to cloud environments, where misconfigurations may expose internal interfaces, noting that three of seven tested open-source projects have not yet implemented any fixes.

Read at Help Net Security

Help Net Security publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store