P1Security
The most damaging things we find in 5G core pentests are almost never exotic.
Our new whitepaper collects what P1 Security's team actually finds when it tests production and pre-production 5G standalone cores. Five recurring classes:
- Authentication and access control: default credentials, hardcoded secrets, reused root SSH keys
- Remote code execution, still most often in the OAM domain
- Privilege escalation, including Kubernetes pod-to-cluster and pod-to-host
- Server-side request forgery in the SBI, turning the SCP or a SEPP into an internal scanner
- Denial of service in the SBI, usually a robustness failure rather than a traffic flood
It also covers three risks that mature 5G SA and inter-operator roaming will make more prominent, and closes with an operator readiness checklist you can take straight into a review.
Download it from here: https://www.p1sec.com/white-paper/top-5g-core-security-vulnerabilities
We are at LEAP 2026 in Riyadh, 31 August to 3 September. Vikas Sharma is there for P1 Security.
Not exhibiting, just taking meetings. If you operate a mobile network in the region, regulate one, or run critical services on top of one, we are happy to compare notes on what the signalling layer actually exposes: SS7, Diameter, GTP, IMS, 5G core and RAN.
contact@p1sec.com
One vendor compromised, and you are inside many 5G cores at once, not one. No internet exposure needed.
In our AMF Under Pressure webinar, El Mehdi Regragui walks the supply chain path into the 5G core: malicious code shipped inside a network function, arriving as a rogue NF already trusted on the SBI.
Full session, 1h11 including the Q&A:
https://watch.getcontrast.io/watch/p1-security-amf-under-pressure-5g-core-security-risks-attack-paths-and-lessons-learned?utm_source=mastodon&utm_medium=social&utm_campaign=webinar-18-amf-clips
Live in under an hour: AMF Under Pressure.
N1, N2, SBI. Three interfaces into the AMF, each trusting a different neighbour. El Mehdi Regragui walks through the attack paths across each, from P1 Security penetration testing and vulnerability research on the 5G core, plus why the OAM and container layer widens the blast radius.
Today, Wednesday 29 July, 15:00 to 16:00 CET. Replay for everyone who registers.
The AMF terminates three interfaces, each trusting a different neighbour: the device (N1/NAS), the radio (N2/NGAP), and peer NFs over HTTP/2 (SBI).
Three interfaces, three classes of risk. Free webinar on the attack paths on each, and the mitigations we recommend. Wed 29 July, 15:00 to 16:00 CET.
5G standalone doesn't run on SS7 or Diameter. Inside the core, network functions talk over a service-based architecture: HTTP/2, JSON, REST APIs on the SBI, discovery via the NRF, trust via TLS and OAuth2 tokens.
Good for agility, but it imports web-app risk into the core: broken authorization between NFs, over-broad tokens, injection, weak TLS. API attacks, not signaling, so SS7 rules never see them.
Your voice core now speaks SIP. VoLTE, VoWiFi and VoNR run on SIP inside the IMS core, so they inherit IP-style risks: spoofing, signalling manipulation, malformed messages and weak transport. At international SIP interconnect, partner trust widens the surface. SBCs alone miss it, which is where telecom-aware SIP IDS earns its place.
Generic IT security was built for IP and web traffic. It does not read SS7, Diameter or GTP-C, so the attacks that hurt operators (location tracking, Diameter abuse, GTP-C misuse, SMS fraud) pass through the firewall undetected.
A telecom IDS is the missing layer. PTM runs passively on live signalling and surfaces attacks, fraud and DoS in real time, on a dashboard SOC and fraud teams can act on.
How it works:
https://www.p1sec.com/product/intrusion-detection-system-ptm
𝗖𝗹𝗼𝘂𝗱 𝗥𝗔𝗡 𝗰𝗵𝗮𝗻𝗴𝗲𝘀 𝘁𝗵𝗲 𝗥𝗔𝗡 𝗮𝘁𝘁𝗮𝗰𝗸 𝘀𝘂𝗿𝗳𝗮𝗰𝗲. 𝗧𝗼𝗺𝗼𝗿𝗿𝗼𝘄, 𝘄𝗲 𝘂𝗻𝗽𝗮𝗰𝗸 𝘄𝗵𝗮𝘁 𝘁𝗵𝗮𝘁 𝗿𝗲𝗮𝗹𝗹𝘆 𝗺𝗲𝗮𝗻𝘀.
As mobile networks move toward virtualised, distributed, and cloud native RAN architectures, the security model changes with them. New interfaces. New operational complexity. New assumptions. And, in some cases, old risks becoming reachable in new ways.
Tomorrow, we will host a technical webinar:
𝗖𝗹𝗼𝘂𝗱 𝗥𝗔𝗡 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆: 𝗘𝘅𝗽𝗹𝗼𝗿𝗶𝗻𝗴 𝗡𝗲𝘄 𝗧𝗵𝗿𝗲𝗮𝘁𝘀
Join Kye Grundy and Laurent Ghigonis for a session on how Cloud RAN deployments reshape exposure across the physical cell site, fronthaul, F1 and E1 interfaces, OAM environments, virtualisation layers, and defensive monitoring.
Expect practical field perspective, technical depth, and a clear look at what operators should consider when assessing Cloud RAN security.
Secure your spot before the live session:
https://watch.getcontrast.io/register/p1-security-cloud-ran-security-exploring-new-threats
One malformed message. That's all it takes.
In our latest write-up, we show how a single UE- or gNB-originated signaling message can travel across the network and crash core functions that are not directly exposed — AMF, SMF, even MME in LTE.
Across both 5G and 4G, the same failure patterns appear:
Parsers assuming well-formed NAS payloads
NGAP handlers trusting mandatory IEs will always be present
EPCO fields that are forwarded untouched until they break the SMF
Stateful procedures that reach "should not happen" branches and terminate
Different stacks. Different protocols. Same outcome:
unexpected input → parser/state failure → process crash
These are not just "open source bugs." They are early warning signals for a wider class of parser and state machine risks that exist across mobile core implementations.
The key lesson is simple: proprietary does not mean fuzz tested. If your 5G or 4G core has not been tested with a stateful, protocol aware fuzzer, assume there are still crash paths hiding in the signaling stack.
Full breakdown here:
https://www.p1sec.com/blog/fuzzing-the-mobile-core-how-malformed-5g-4g-signaling-crashes-production-networks
If you still think APTs only care about endpoints, this webinar will change your threat model.
In Physical to 5G Core Compromise, we break down why telecom infrastructure is a high value target for nation state actors, what they are realistically trying to achieve, and how those objectives map to concrete attack paths across RAN, transport, management, and core.
What you will take away
The attacker goals behind real world telecom intrusions
Where “temporary” operational exceptions turn into long term exposure
How to think about containment and segmentation when the target is the core
Watch the full recording
https://watch.getcontrast.io/register/p1-security-physical-to-5g-core-compromise
Open source keeps telecom innovation moving.
It also needs real protocol level security testing.
At P1 Security, we help open source projects become more robust and secure by identifying implementation weaknesses before attackers get a free lab.
A recent example is 𝐄𝐥𝐥𝐚 𝐂𝐨𝐫𝐞, where our team uncovered multiple AMF denial of service vulnerabilities triggered by malformed NGAP and NAS traffic.
These findings were discovered by Telecom Security Experts at P1 Security.
Their research uncovered a broader pattern of parser and validation weaknesses affecting control plane handling, including:
- invalid NGAP NGReset handling
- short integrity protected NAS payload parsing
- empty NR security capability in PathSwitchRequest
- invalid PDU Session IDs in NGAP messages
- malformed NGAP Location Report handling
- malformed UL NAS Transport without a Request Type
This is exactly why telecom security still requires deep protocol expertise.
Malformed signaling should be rejected safely.
It should not be able to crash an AMF.
We are proud to contribute research that helps strengthen the resilience of open source mobile infrastructure and make the ecosystem safer for everyone.
Discover more on P1 Security contributions and findings on: cve.p1sec.com
Cyber conflict has a long memory.
One point from this TelcoSec Talk replay that really stands out is how certain methods do not just disappear. They resurface, evolve, and show up again in new contexts.
In this clip, Hamid Kashfi touches on that pattern through the Iran cyber landscape, and why looking at single incidents in isolation is rarely enough. The real value comes from understanding how tactics develop over time and how events connect across a longer timeline.
That is also what makes this space so complex to analyze. You are not only looking at technical activity. You are looking at continuity, adaptation, and context.
Replay link:
https://watch.getcontrast.io/register/p1-security-telcosec-talk-v2-iran-cyberwar-telecom-infrastructure
In telecom security, the first problem is often not fixing exposure.
It is **seeing it clearly**.
So we built **TelcoASM Risk Exposure**.
A free assessment tool that helps telecom security professionals quickly visualize risk exposure across mobile network domains and compare their position against aggregated industry benchmarks.
No heavy process. No full audit. No endless spreadsheet archaeology.
Just a fast, structured way to answer:
**Where are we exposed, and what should we look at first?**
TelcoASM provides:
• Benchmarking against industry exposure patterns
• A visual heatmap across 4G and 5G RAN, Packet Core, IMS, and legacy environments
• Business impact mapping
• High risk gap identification
• Actionable next steps aligned with GSMA and 3GPP standards
It takes only a few minutes to complete.
Run the assessment here: https://telcoasm.p1sec.com/
Because sometimes the biggest security gap is not in the network. It is in the visibility.
#TelecomSecurity #MobileSecurity #5G #4G #CyberRisk #AttackSurface #Telecom #NetworkSecurity #SecurityAssessment #P1Security

