# Baicells Nova 430H eNodeB DoS flaw unpatched

Published: 2026-09-29 · Severity: routine · Sectors: telecommunications, technology
Canonical: https://vorant.io/reports/b5808b25-747e-57bf-ac1a-e4aa28735f28/baicells-nova-430h-enodeb-dos-flaw-unpatched

> An unauthenticated attacker in radio range can crash cell signaling on Baicells Nova 430H eNodeBs via a malformed uplink message; no fix is planned.

CISA has published an ICS advisory for a denial-of-service vulnerability (CVE-2026-96274) affecting Baicells Nova 430H eNodeB devices (model pBS3101SH) running BaiBLQ_3.0.12 or earlier. The flaw stems from improper validation of an NAS payload within an uplink message sent during connection setup; an unauthenticated device within radio range can craft a malformed message that the eNodeB forwards to the core network, triggering a shutdown of the signaling association for the affected cell. This causes a temporary service disruption until connectivity is re-established between the eNodeB and core network.

The vulnerability requires physical radio-range proximity and is not remotely exploitable over the internet. Baicells has not responded to CISA's outreach and no fix is currently planned, leaving affected operators without a vendor remediation path. CISA recommends standard network isolation practices — minimizing exposure of control system devices, segmenting them behind firewalls away from business networks, and using VPNs for any necessary remote access — though these mitigations primarily address network-layer exposure rather than the radio-range attack vector itself.

No known public exploitation has been reported. Given the lack of a patch, affected operators (communications and IT sector organizations using this eNodeB model) should contact Baicells support directly for guidance and consider compensating controls such as monitoring for signaling anomalies or restricting physical/RF access to deployment sites.

## Mentioned in this report

- Vulnerabilities: CVE-2026-96274

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-04

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b5808b25-747e-57bf-ac1a-e4aa28735f28/baicells-nova-430h-enodeb-dos-flaw-unpatched.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
