Academic researchers from Nanyang Technological University identified 84 security vulnerabilities across 4G and 5G core network infrastructure. These flaws form what the team describes as a "widespread class" of defects that expose telecommunications networks to serious attacks.

The vulnerabilities enable two primary attack vectors. Denial-of-service attacks could disrupt network availability and service delivery to end users. More critically, session hijacking attacks allow threat actors to intercept and assume control of active user network sessions, granting unauthorized access to subscriber data and communications.

4G and 5G core networks handle authentication, billing, and call routing for billions of mobile subscribers worldwide. Compromise of these systems affects not just individual users but entire telecommunications infrastructure serving cities and regions. The session hijacking risk is particularly acute because core network access typically requires no additional verification once a session is established.

The research targets the fundamental protocols governing how mobile devices authenticate to networks and maintain connectivity. Rather than exploiting implementation bugs in specific vendor equipment, these vulnerabilities reflect design-level issues in how the 4G and 5G standards themselves handle session management and authentication handoffs.

Telecommunications providers must evaluate their core network deployments against the disclosed vulnerability classes. Mitigation strategies likely include protocol-level patches, enhanced session validation mechanisms, and stricter access controls on core network interfaces. Equipment vendors will need to release firmware updates addressing the identified flaws.

The timing of this disclosure is significant. 5G networks remain in active deployment globally, and many operators continue running 4G infrastructure that will operate for years. A widespread vulnerability class affecting both generations simultaneously presents a substantial patching burden across the industry.

Researchers typically coordinate disclosure timelines with affected vendors before public release, allowing preparation time before attack tools emerge. Organizations operating telecommunications infrastructure should prioritize understanding which of the 84 flaws apply to their specific deployments and equipment vendors, then prioritize patches addressing