RANsacked: A Domain-Informed Approach for Fuzzing LTE and 5G RAN-Core Interfaces
Nathaniel Bennett, Weidong Zhu, Benjamin Simon, Ryon Kennedy, William Enck, Patrick Traynor, Kevin R. B. Butler
Abstract
Cellular network infrastructure serves as the backbone of modern mobile wireless communication. As such, cellular cores must be proactively secured against external threats to ensure reliable service. Compromised base station attacks against the core are a rising threat to cellular networks, while user device inputs have long been considered as an attack vector; despite this, few techniques exist to comprehensively test RAN-Core interfaces against malicious input. In this work, we devise a fuzzing framework that performantly fuzzes cellular interfaces accessible from a base station or user device, overcoming several challenges in fuzzing specific to LTE/5G network components. We also introduce ASNFuzzGen, a tool that compiles ASN.1 specifications into structure-aware fuzzing modules, thereby facilitating effective fuzzing exploration of complex cellular protocols. We run fuzzing campaigns against seven open-source and commercial cores and discover 119 vulnerabilities, with 93 CVEs assigned. Our results reveal common implementation mistakes across several cores that lead to vulnerabilities, and the successful coordination of patches for these vulnerabilities across several vendors demonstrates the practical impact ASNFuzzGen has on hardening user-exposed cellular systems. CCS CONCEPTS • Security and privacy → Mobile and wireless security; Software and application security; • Networks → Mobile networks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext acd54871-460b-40ac-bcfb-4314ef86c6c1Cited by top-tier papers10
- Uncovering Hidden Paths in 5G: Exploiting Protocol Tunneling and Network Boundary BridgingAltaf Shaik, Robert Jaschek, Jean-Pierre SeifertCCS 2025 · 1 citation
- SIPConfusion: Exploiting SIP Semantic Ambiguities for Caller ID and SMS SpoofingQi Wang, Jianjun Chen, Jingcheng Yang, Jiahe Zhang et al.NDSS 2026 · 1 citation
- Small Cell, Big Risk: A Security Assessment of 4G LTE Femtocells in the WildYaru Yang, Yiming Zhang, Tao Wan, Haixin Duan et al.NDSS 2026 · 1 citation
- CITesting: Systematic Testing of Context Integrity Violations in LTE Core NetworksMincheol Son, Kwangmin Kim, Beomseok Oh, CheolJun Park et al.CCS 2025
- VUPER: Verified ASN.1 UPER ParserXiaotian Zhou, Kai Tu, Ali Ranjbar, Yilu Dong et al.CCS 2026
Builds on11
- Evaluating Fuzz TestingGeorge Klees, Andrew Ruef, Benji Cooper, Shiyi Wei et al.CCS 2018 · 753 citations
- REDQUEEN: Fuzzing with Input-to-State CorrespondenceCornelius Aschermann, Sergej Schumilo, Tim Blazytko, Robert Gawlik et al.NDSS 2019 · 413 citations
- NAUTILUS: Fishing for Deep Bugs with GrammarsCornelius Aschermann, Tommaso Frassetto, Thorsten Holz, Patrick Jauernig et al.NDSS 2019 · 291 citations
- LTEInspector: A Systematic Approach for Adversarial Testing of 4G LTESyed Rafiul Hussain, Omar Chowdhury, Shagufta Mehnaz, Elisa BertinoNDSS 2018 · 225 citations
- Touching the Untouchables: Dynamic Security Analysis of the LTE Control PlaneHongil Kim, Jiho Lee, Eunkyu Lee, Yongdae KimS&P 2019 · 174 citations
Related papers
- 5GC-Fuzz: Finding Deep Stateful Vulnerabilities in 5G Core Network with Black-Box FuzzingYu Sun, Xinyu Liu, Qian Sun, Jiaming Wang et al.INFOCOM 2025 · 5 citations
- Stateful Analysis and Fuzzing of Commercial Baseband FirmwareAli Ranjbar, Tianchang Yang, Kai Tu, Saaman Khalilollahi et al.S&P 2025
- CoreCrisis: Threat-Guided and Context-Aware Iterative Learning and Fuzzing of 5G Core NetworksYilu Dong, Tianchang Yang, Abdullah Al Ishtiaq, Syed Md. Mukit Rashid et al.USENIX Security 2025
- Formal Analysis of Access Control Mechanism of 5G Core NetworkMujtahid Akon, Tianchang Yang, Yilu Dong, Syed Rafiul HussainCCS 2023 · 21 citations
- Bookworm Game: Automatic Discovery of LTE Vulnerabilities Through Documentation AnalysisYi Chen, Yepeng Yao, XiaoFeng Wang, Dandan Xu et al.S&P 2021 · 57 citations
