Researchers at Singapore’s Nanyang Technological University have built an agentic AI tool called iFinder that discovered 84 vulnerabilities in open-source software controlling the core of 4G and 5G mobile networks. The flaws span seven implementations including Open5GS, free5GC and OpenAirInterface. Developers confirmed 83 of them, 81 received CVE identifiers and 58 have been patched. The most critical issue allows an attacker to redirect a subscriber’s internet traffic. The team recreated the session-hijacking flaw in controlled tests of two commercial 5G cores. Most of the problems stem from core network functions accepting messages from one another without verification, a practice inherited from physically isolated environments. As networks become software-defined and cloud-hosted, that implicit trust amplifies risk. iFinder uses multiple AI agents to prepare 3GPP documents, search source code, vet candidates and build proof-of-concept tests.
Researchers at Singapore’s Nanyang Technological University have built an agentic AI tool called iFinder that discovered 84 vulnerabilities in open-source software controlling the core of 4G and 5G mobile networks. The flaws span seven implementations including Open5GS, free5GC and OpenAirInterface. Developers confirmed 83 of them, 81 received CVE identifiers and 58 have been patched. The most critical issue allows an attacker to redirect a subscriber’s internet traffic. The team recreated the session-hijacking flaw in controlled tests of two commercial 5G cores. Most of the problems stem from core network functions accepting messages from one another without verification, a practice inherited from physically isolated environments. As networks become software-defined and cloud-hosted, that implicit trust amplifies risk. iFinder uses multiple AI agents to prepare 3GPP documents, search source code, vet candidates and build proof-of-concept tests.