Exposing IMSI Vulnerabilities in 5G Standalone Networks

Ian Joseph Matheus Edward, Hamonangan Situmorang, Jeremy Aditya · 2025

The development of 5G has transformed the way people communicate with one another. With its ultra-high speeds, low latency, and massive connection capabilities, 5G allows the development of modern applications and services. That advancement, however, comes with serious security concerns. Particularly with the persistence of legacy vulnerabilities such as IMSI exposure. Therefore, there needs to be a system that are able to prevent the misuse of such vulnerabilities. This paper presents the design and evaluation of a rogue 5G Standalone (SA) network testbed that are capable of capturing International Mobile Subscriber Identity (IMSI) values during initial User Equipment (UE) registration. By replicating legitimate network configuration and leveraging known authentication credentials, the system successfully attracts UEs and extracts their IMSI without disrupting the legitimate network connectivity. Experimental results confirm the system’s ability to operate covertly and consistently, emphasizing the ongoing privacy risks in real-world 5G deployments.

Read the paper · More papers on PaperTik