The record
Written from the 1 report below. Nothing here is unsourced.
- Researchers at Nanyang Technological University disclosed 84 vulnerabilities in 4G and 5G core network implementations, alongside CVE-2026-8233 affecting Dotouch XproUPF 2.0.0-release-088aa7c4.
- The Dotouch flaw involves improper access controls in an unknown UPF function and carries a CVSS of 4.6 (medium), requiring adjacent network access and low privileges.
- The broader NTU research uncovered flaws across multiple open-source and commercial 5G core stacks — including Open5GS, OpenAirInterface, free5GC, SD-Core, and eUPF — enabling denial-of-service and session hijacking.
- Public proof-of-concept code is available for some of these issues, raising exploitation risk despite the medium severity of the Dotouch CVE specifically.
- Patches have been released for some vendors while others are still remediating.
- Operators of affected 5G core infrastructure should inventory their stacks, apply available patches, and enforce strict boundary access controls while awaiting remaining fixes.
What to watch next
- Inventory 5G core components against affected vendor list
- Apply released patches; track remaining vendor remediations
- Enforce network segmentation and access controls around UPF
- Monitor for PoC exploitation targeting telecom infrastructure
Why it matters4
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- Dotouch XproUPF deployments improper access control· days
- 4G/5G core network operators using Open5GS, OpenAirInterface, free5GC, SD-Core, eUPF session hijacking risk· days
- 4G/5G core network operators denial of service risk· days
- Telecom vendors and operators patch required· weeks
Coverage1
1 report
English national1
Filed from India ×1, United States ×1
Named Dotouch · eUPF · Free5Gc · Open5Gs · Openairinterface · SD-Core · XproUPF · Nanyang Technological University · Ziyu Lin
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
