Radio-Range Flaw Can Disrupt Baicells Nova 430H Cellular Service
CVE-2026-96274 lets attackers in radio range disrupt Baicells Nova 430H service via malformed NAS messages. No patch planned; mitigation guidance inside.
Illustrative image generated with AI
A high-severity vulnerability in Baicells Nova 430H eNodeB equipment allows an unauthenticated device within radio range to interrupt cellular service by transmitting a malformed connection message.
CISA disclosed the issue in advisory ICSA-26-272-04 on September 29, 2026. The vulnerability, tracked as CVE-2026-96274, affects Nova 430H model pBS3101SH devices running BaiBLQ_3.0.12 or earlier.
There is no planned fix. CISA also said Baicells Technologies did not respond to requests to collaborate on mitigation, leaving operators to manage the exposure through network architecture, monitoring, and other defensive controls.
Malformed NAS traffic can break the signaling association
CVE-2026-96274 is an uncaught-exception vulnerability classified as CWE-248. It arises during the connection setup process between a radio device, the Baicells eNodeB, and the cellular core network.
An attacker within radio range can send a malformed uplink message containing an invalid Non-Access Stratum, or NAS, payload. NAS messages support control functions between user equipment and the core network, while the eNodeB carries those messages across the radio access network.
The Nova 430H does not adequately validate the invalid payload before forwarding it to the core. Processing that payload can cause the cell’s signaling association to shut down.
Service remains disrupted until the eNodeB and core network establish connectivity again. The available information describes this as a temporary availability failure rather than a persistent compromise.
The attack does not require authentication or user interaction, and its complexity is rated low. However, the attacker must have adjacent radio access. CISA therefore describes CVE-2026-96274 as not remotely exploitable, meaning the disclosed attack cannot simply be launched against the device from an arbitrary internet location.
That distinction does not make the flaw harmless. Someone with suitable equipment near an affected deployment could potentially trigger the failure without first obtaining an account or compromising the operator’s internal network.
BaiBLQ_3.0.12 and all earlier versions are affected
The affected product is the Baicells Technologies Nova 430H eNodeB, specifically model pBS3101SH. The vulnerable software range covers versions from 0 through BaiBLQ_3.0.12, inclusive.
CISA expresses the affected range as:
<= BaiBLQ_3.0.12
The vulnerability has a high severity rating under both current scoring systems:
- CVSS 3.1: 7.4
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H - CVSS 4.0: 8.3
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Both vectors characterize availability as the principal security consequence. They assign no confidentiality or integrity impact, reflecting the absence of a disclosed mechanism for reading protected information or modifying system data.
The CVSS 3.1 vector marks scope as changed because the malformed traffic crosses a security boundary: the eNodeB forwards the payload to the core network, where processing causes the signaling failure. The CVE Program record confirms the product, affected versions, weakness classification, severity scores, and technical description.
Communications operators face a localized denial-of-service risk
Baicells Nova 430H equipment is deployed worldwide, and CISA associates the affected product with the Communications and Information Technology critical-infrastructure sectors. Baicells is headquartered in the United States.
The immediate consequence for an operator is loss of availability at the affected cell. Users relying on that cell may experience a service interruption while the eNodeB and core restore their signaling connection.
The published assessment does not describe data theft, unauthorized configuration changes, code execution, or persistent access. It also does not establish that one malformed transmission could disrupt other cells or broader portions of an operator’s network.
No public exploitation specifically targeting CVE-2026-96274 is known. No indicators of compromise, malicious payload samples, or detection signatures have been published.
CVE-2026-96274 is not reported as having been added to CISA’s Known Exploited Vulnerabilities catalog, and no KEV remediation deadline has been provided. The disclosure therefore documents an exploitable condition, but not a confirmed active-exploitation campaign.
Qiqing Huang reported the vulnerability to CISA.
No vendor patch is planned
CISA reports that no fix is planned for the vulnerable Nova 430H releases. The agency also says Baicells did not respond to its attempts to coordinate mitigation work.
Consequently, there is no disclosed patched version to which operators can upgrade. Organizations using the affected model should contact Baicells customer support directly for product-specific information, possible configuration guidance, and any change in remediation status.
Operators should first identify Nova 430H pBS3101SH units and record their installed software versions. Any device running BaiBLQ_3.0.12 or an earlier release falls within the disclosed vulnerable range.
Because exploitation occurs over the radio interface, conventional internet perimeter filtering cannot eliminate the underlying attack path. Network isolation can still reduce secondary exposure and limit access to management and control components, but it does not validate the malformed NAS payload at the vulnerable processing point.
Organizations should also review operational logs and alarms for unexplained signaling-association shutdowns, repeated reconnection events, or temporary cell outages. These events are not definitive evidence of exploitation, since ordinary faults may produce similar symptoms. They can nevertheless support investigation when correlated with radio activity and core-network telemetry.
Defense-in-depth is the only current mitigation path
CISA recommends minimizing the network exposure of control-system devices and ensuring that they are not directly accessible from the internet. Control-system networks and remote equipment should sit behind firewalls and remain isolated from business environments.
Where remote access is operationally necessary, organizations should use more secure access methods such as maintained VPN infrastructure. They must also account for the security of endpoints connecting through those remote-access channels, since a VPN does not protect an environment from an already compromised client.
Before introducing new filtering, isolation, or monitoring controls, operators should conduct an impact analysis and risk assessment. Changes affecting cellular signaling or core connectivity can themselves create availability problems if deployed without testing.
CISA points operators toward its defense-in-depth recommendations for industrial control systems and technical paper ICS-TIP-12-146-01B, which covers targeted intrusion detection and mitigation strategies. Suspected malicious activity should be handled under established incident-response procedures and reported to CISA for correlation and tracking.
The agency also repeats its general warnings about unsolicited email, links, attachments, phishing, and social engineering. Those precautions do not address the radio-layer flaw directly, but they remain relevant to protecting the administrative systems surrounding affected deployments.
Until Baicells provides a product correction, operators have no direct software remedy for CVE-2026-96274. Asset identification, architectural isolation, resilient recovery procedures, and monitoring for abnormal signaling failures are the practical controls currently available.
Sources
This article is an original reworking based on the sources below.
- primary sourceCVE Program
- CISA Advisories




