DEF CON 33 - Pre-Auth RCE, Arbitrary SMS & Adjacent Attacks on 5G and 4G_LTE Routers - Edward Warren

DEF CON 33 - Pre-Auth RCE, Arbitrary SMS & Adjacent Attacks on 5G and 4G_LTE Routers - Edward Warren

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 27:13

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The speaker reveals widespread, systemic security flaws in 5G and 4G routers, particularly due to insecure firmware and poor coding practices like unvalidated input and default credentials, enabling remote code execution and arbitrary SMS sending. 1:00

Key Takeaways:
• Insecure firmware with exposed API endpoints and default credentials (admin/admin!) enables unauthorized access in 5G and 4G routers 1:30.
• The use of Go form in router SDKs is a recurring vulnerability across manufacturers, leading to command injection and remote code execution 2:48.
• Devices allow unauthenticated access to critical functions like SMS sending via AT commands, enabling information disclosure and potential misuse 23:33.
• A lack of input sanitization in parameters like Wi-Fi name and APN settings allows command injection and buffer overflow vulnerabilities 18:48.
• The research highlights that these devices are reachable over the internet despite being designed for private networks, exposing users to remote attacks 13:00.

The presentation underscores the urgent need for manufacturers to adopt secure software development practices and maintain transparent software bills of materials to prevent exploitable flaws in IoT devices. 26:54

Sources:

  • 1:00 Overview of research focus on insecure 5G/4G routers and pre-authentication code execution.
  • 1:30 Discussion of insecure default credentials and access control flaws in routers.
  • 2:48

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Ladies and gentlemen, hacking hotspots with Edward. Here we go. [Applause] >> Good afternoon everyone. I want to thank everyone for for for just taking the time. I know this has been a long day. You know, we're about to wrap up Defcon. This is my first Defcon and it's so surreal to even be here. So I just want to thank the entire community, all the hardworking staff and volunteers. So this talks about hacking hotspots, pre-author mode code execution, arbitrary SMS and adjacent attacks on 5G and LTE routers. I'm going to go ahead and just move forward. So before I get started, I just want to go over an agenda. We have the the staple who am I? I'm going to go over some related work. Um when it comes to the the devices, I'll be referring to the the Wi-Fi routers. We're going to be talking abo…