Abstract
The emergence of the 5G Open Radio Access Network (O-RAN) architecture introduces increased flexibility and
modularity to cellular networks, but its sudden shift toward
software-centric and multi-vendor deployments also expands the
software supply chain (SSC) attack surface, which is particularly
concerning given the critical role of 5G infrastructure. SSC
vulnerabilities can lead to severe consequences, including service
disruption, unauthorized backdoors, and code injection. In this
work, we systematically identify and analyze SSC vulnerabilities
in O-RAN Radio Intelligent Controller (RIC), which performs latency sensitive edge control and optimization in 5G networks. Using static analysis tools, we evaluate production-grade O-RAN
components primarily implemented in Go and find 57 security relevant issues after manual validation. We highlight key limitations of off-the-shelf analyzers, quantify false-positive results, and
contextualize identified risks within O-RAN deployments. Our
findings emphasize the need for improved SSC security practices
tailored to O-RAN systems.
modularity to cellular networks, but its sudden shift toward
software-centric and multi-vendor deployments also expands the
software supply chain (SSC) attack surface, which is particularly
concerning given the critical role of 5G infrastructure. SSC
vulnerabilities can lead to severe consequences, including service
disruption, unauthorized backdoors, and code injection. In this
work, we systematically identify and analyze SSC vulnerabilities
in O-RAN Radio Intelligent Controller (RIC), which performs latency sensitive edge control and optimization in 5G networks. Using static analysis tools, we evaluate production-grade O-RAN
components primarily implemented in Go and find 57 security relevant issues after manual validation. We highlight key limitations of off-the-shelf analyzers, quantify false-positive results, and
contextualize identified risks within O-RAN deployments. Our
findings emphasize the need for improved SSC security practices
tailored to O-RAN systems.
| Original language | American English |
|---|---|
| State | Published - Feb 23 2026 |
| Event | 2026 NDSS Future G Workshop - San Diego, United States Duration: Feb 23 2026 → Feb 27 2026 |
Conference
| Conference | 2026 NDSS Future G Workshop |
|---|---|
| Country/Territory | United States |
| City | San Diego |
| Period | 02/23/26 → 02/27/26 |
Keywords
- 5G
- Open RAN
- Supply Chain Risk
INL Publication Number
- INL/CON-26-90884
- 213173
Fingerprint
Dive into the research topics of 'Assessing Supply Chain Risks in 5G O-RAN Components Using Static Analysis'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver