CVE-2026-8233: A vulnerability was determined in Dotouch XproUPF 2.0.0-release-088aa7c4. Affected is an unknown function of the component UPF. This manipulation causes imprope
CVE-2026-8233 disclosed: A vulnerability was determined in Dotouch XproUPF 2.0.0-release-088aa7c4. Affected is an unknown function of the component UPF. This manipulation causes improper access controls. A high degree of comp

Through the Reader lens — Researchers at Nanyang Technological University disclosed 84 vulnerabilities in 4G and 5G core network implementations, alongside CVE-2026-8233 affecting Dotouch XproUPF 2.0.0-release-088aa7c4. The Dotouch flaw involves improper access controls in an unknown UPF function and carries a CVSS of 4.6 (medium), requiring adjacent network access and low privileges. The broader NTU research uncovered flaws across multiple open-source and commercial 5G core stacks — including Open5GS, OpenAirInterface, free5GC, SD-Core, and eUPF — enabling denial-of-service and session hijacking. Public proof-of-concept code is available for some of these issues, raising exploitation risk despite the medium severity of the Dotouch CVE specifically. Patches have been released for some vendors while others are still remediating. Operators of affected 5G core infrastructure should inventory their stacks, apply available patches, and enforce strict boundary access controls while awaiting remaining fixes.
What to watch next
- Inventory 5G core components against affected vendor list
- Apply released patches; track remaining vendor remediations
- Enforce network segmentation and access controls around UPF
- Monitor for PoC exploitation targeting telecom infrastructure
