CISA Flags Baicells Nova 430H DoS Bug, No Vendor Fix Planned
A malformed NAS payload over the air can knock a cell offline, and Baicells hasn't responded to CISA's coordination requests, leaving operators with nothing but network hardening.
TL;DR
CISA disclosed CVE-2026-96274, a CVSS 7.4 unauthenticated denial-of-service vulnerability in Baicells Nova 430H eNodeB (model pBS3101SH) running firmware through BaiBLQ_3.0.12. An attacker within radio range can send a malformed NAS payload during connection setup that the eNodeB forwards to the core network, triggering a shutdown of the cell's signaling association. Baicells hasn't responded to CISA's vendor coordination outreach and no fix is planned. The equipment is deployed worldwide in the Communications and IT sectors.
The advisory lands as the latest in a string for Baicells eNodeB gear. The Nova product line has seen command-injection vulnerabilities with CVSS 9.8 scores in 2023 (CVE-2023-0776, CVE-2023-24508), hardcoded-credential issues spanning multiple models (CVE-2022-24693, CVE-2023-24022), and now this radio-range DoS. Baicells shipped firmware updates for the 2023 command-injection bugs; this time around, CISA's disclosure states plainly that the vendor hasn't engaged.
The vulnerability itself is straightforward. During LTE connection setup, a device in radio range sends an uplink message containing a crafted NAS payload. The eNodeB doesn't validate it before forwarding it to the core network. The core network responds by tearing down the signaling association for the cell, and service drops until re-establishment completes.
The CVSS 3.1 vector tells the operational story: adjacent attack vector, low complexity, no privileges, no user interaction, scope changed, and availability impact high. In CVSS 4.0 terms, it's an 8.3. The confidentiality and integrity impacts are nil, so this isn't a data-exfiltration or remote-code-execution scenario. But for a cell site serving municipal or campus coverage, repeated DoS triggering could disrupt service without leaving an obvious forensic trail beyond radio logs.
CISA's recommended mitigations (network segmentation, firewalls, VPNs) are the standard ICS advisory boilerplate. They don't directly address a radio-range attack vector. An operator's practical options narrow to: isolating affected eNodeBs behind additional radio-layer monitoring, restricting physical proximity to installations where feasible, and contacting Baicells support directly for any unpublished workaround guidance.
Organizations with these units in production (municipal networks, private LTE deployments on government or campus sites, and any facility where the Nova 430H provides local cell coverage) should inventory the firmware versions and assess whether the cell's availability risk tolerates an undefined remediation timeline.
Published ·Deep Fathom