CISA Warns of Critical Denial-of-Service Vulnerability in Baicells Nova 430H
CISA has issued a critical advisory for a denial-of-service vulnerability in Baicells Nova 430H eNodeB devices, impacting cellular network availability.

The Cybersecurity and Infrastructure Security Agency (CISA) has released a critical advisory detailing a significant vulnerability affecting Baicells Nova 430H eNodeB devices. Identified as CVE-2026-96274, the flaw could allow an unauthenticated attacker within radio range to disrupt cellular services, leading to temporary outages.
The vulnerability stems from an uncaught exception that occurs when the eNodeB device improperly handles malformed messages during the connection setup process. Specifically, an attacker can send an invalid NAS payload in an uplink message. The Nova 430H eNodeB, running firmware version BaiBLQ_3.0.12 or earlier, does not adequately validate this payload. Instead, it forwards the malformed message to the core network, triggering a shutdown of the signaling association for the affected cell.
Successful exploitation of this vulnerability results in a denial-of-service condition, causing a temporary disruption of service. The affected cell will remain offline until the eNodeB and the core network can re-establish connectivity. While the vulnerability is not exploitable remotely and requires the attacker to be within radio range, its impact on critical communications infrastructure is significant.
CISA has assigned a CVSS v3.1 base score of 7.4 (HIGH) to this vulnerability, citing an attack vector of adjacent (AV:A), low complexity (AC:L), no privileges required (PR:N), no user interaction needed (UI:N), a scope change (S:C), and a high impact on availability (A:H). A CVSS v4.0 score of 8.3 (HIGH) further emphasizes the severity, with an adjacent attack vector and high availability impact.
Baicells Technologies has indicated that no fix is currently planned for this vulnerability. The company has not responded to CISA's requests to collaborate on mitigating the issue. Users of affected Baicells Nova 430H eNodeB devices are advised to contact Baicells customer support for potential workarounds or additional information regarding the vulnerability.
CISA strongly recommends that organizations implement defensive measures to minimize the risk of exploitation. These measures include minimizing network exposure for all control system devices, ensuring they are not accessible from the internet, and locating control system networks behind firewalls and isolating them from business networks. When remote access is necessary, secure methods like Virtual Private Networks (VPNs) should be utilized, ensuring they are kept updated.
While no known public exploitation targeting this specific vulnerability has been reported to CISA at this time, the advisory serves as a crucial warning for operators of critical infrastructure. The vulnerability affects Baicells Nova 430H eNodeB devices, model pBS3101SH, with firmware versions less than or equal to BaiBLQ_3.0.12. The devices are deployed globally within the Communications and Information Technology sectors.
This advisory highlights the ongoing need for vigilance in securing industrial control systems (ICS) and operational technology (OT) environments. The potential for denial-of-service attacks on communication infrastructure underscores the importance of robust vulnerability management and timely patching, even when vendors are unresponsive.