An AI tool found 84 flaws in 5G network software and 23 of them still have no fix
Researchers at Nanyang Technological University employed an AI agent pipeline called iFinder to audit 4G and 5G network infrastructure, identifying 84 previously undisclosed security vulnerabilities. Of these, developers have confirmed 83, with 81 assigned CVE numbers, though 23 confirmed issues currently lack a patch.
The most severe finding enables an attacker to hijack a subscriber's data session by injecting a fraudulent forwarding rule with higher priority into internal network links. This flaw was successfully exploited end-to-end against the open-source OpenAirInterface 5G core and subsequently validated on two commercial 5G core networks, including one major carrier. While one vendor issued a fix designated as CVE-2026-8233, the other remains in remediation. The study highlights risks associated with migrating core functions to cloud environments, where misconfigurations may expose internal interfaces, noting that three of seven tested open-source projects have not yet implemented any fixes.