<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-96274 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-96274/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 16:24:50 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-96274/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Denial-of-Service Vulnerability in Baicells Nova 430H eNodeB</title><link>https://feed.craftedsignal.io/briefs/2026-09-baicells-nova-430h-dos/</link><pubDate>Tue, 29 Sep 2026 16:24:50 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-baicells-nova-430h-dos/</guid><description>An unauthenticated attacker within radio range can trigger a denial-of-service on the Baicells Nova 430H eNodeB by sending malformed NAS payloads during connection setup (CVE-2026-96274).</description><content:encoded><![CDATA[<p>The Baicells Nova 430H eNodeB (model pBS3101SH), specifically versions up to and including BaiBLQ_3.0.12, is susceptible to a denial-of-service vulnerability tracked as CVE-2026-96274. The vulnerability arises from an uncaught exception (CWE-248) when the device fails to properly validate the Non-Access Stratum (NAS) payload within an uplink message during the initial connection setup process. An unauthenticated attacker within radio range of the device can exploit this by transmitting a malformed message. Upon receipt, the eNodeB inadvertently forwards the invalid payload to the core network, causing a collapse of the signaling association. This results in a persistent service disruption for the affected cell until connectivity is manually re-established between the eNodeB and the core. Baicells has not provided a patch or remediation plan for this issue.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The attacker positions themselves within the radio range of the targeted Baicells Nova 430H eNodeB.</li>
<li>The attacker initiates a connection request to the eNodeB using standard radio signaling protocols.</li>
<li>During the subsequent connection setup phase, the attacker crafts a malicious uplink NAS payload.</li>
<li>The attacker transmits the malformed payload to the eNodeB.</li>
<li>The eNodeB fails to validate the structure or contents of the received NAS payload.</li>
<li>The eNodeB forwards the invalid payload to the connected core network.</li>
<li>The core network rejects the signaling due to the malformed data, resulting in a shutdown of the signaling association.</li>
<li>The cell becomes unavailable, causing a denial-of-service for users attempting to connect to that base station.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>This vulnerability impacts critical infrastructure within the Communications and Information Technology sectors worldwide. A successful attack results in the loss of service for the targeted eNodeB, preventing legitimate users from accessing network connectivity. Given the nature of the device as a radio access point, the impact is focused on the availability of cellular services. There is no patch available for this vulnerability, and as of the reporting date, no active exploitation in the wild has been confirmed.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Minimize exposure of control system devices by ensuring the eNodeB management interfaces are not accessible from the public internet.</li>
<li>Implement network segmentation by placing remote devices behind firewalls and isolating them from internal business networks.</li>
<li>Utilize encrypted VPN tunnels for all remote management access to the eNodeB infrastructure.</li>
<li>Review internal incident response procedures for handling localized denial-of-service events related to radio access network infrastructure.</li>
<li>Contact Baicells customer support for further information regarding potential configuration workarounds, as no firmware update is planned.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>denial-of-service</category><category>ics</category><category>cve-2026-96274</category></item></channel></rss>