{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/baicells-technologies/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Nova 430H eNodeB (\u003c=BaiBLQ_3.0.12)"],"_cs_severities":["high"],"_cs_tags":["denial-of-service","ics","cve-2026-96274"],"_cs_type":"threat","_cs_vendors":["Baicells Technologies"],"content_html":"\u003cp\u003eThe Baicells Nova 430H eNodeB (model pBS3101SH), specifically versions up to and including BaiBLQ_3.0.12, is susceptible to a denial-of-service vulnerability tracked as CVE-2026-96274. The vulnerability arises from an uncaught exception (CWE-248) when the device fails to properly validate the Non-Access Stratum (NAS) payload within an uplink message during the initial connection setup process. An unauthenticated attacker within radio range of the device can exploit this by transmitting a malformed message. Upon receipt, the eNodeB inadvertently forwards the invalid payload to the core network, causing a collapse of the signaling association. This results in a persistent service disruption for the affected cell until connectivity is manually re-established between the eNodeB and the core. Baicells has not provided a patch or remediation plan for this issue.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker positions themselves within the radio range of the targeted Baicells Nova 430H eNodeB.\u003c/li\u003e\n\u003cli\u003eThe attacker initiates a connection request to the eNodeB using standard radio signaling protocols.\u003c/li\u003e\n\u003cli\u003eDuring the subsequent connection setup phase, the attacker crafts a malicious uplink NAS payload.\u003c/li\u003e\n\u003cli\u003eThe attacker transmits the malformed payload to the eNodeB.\u003c/li\u003e\n\u003cli\u003eThe eNodeB fails to validate the structure or contents of the received NAS payload.\u003c/li\u003e\n\u003cli\u003eThe eNodeB forwards the invalid payload to the connected core network.\u003c/li\u003e\n\u003cli\u003eThe core network rejects the signaling due to the malformed data, resulting in a shutdown of the signaling association.\u003c/li\u003e\n\u003cli\u003eThe cell becomes unavailable, causing a denial-of-service for users attempting to connect to that base station.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThis vulnerability impacts critical infrastructure within the Communications and Information Technology sectors worldwide. A successful attack results in the loss of service for the targeted eNodeB, preventing legitimate users from accessing network connectivity. Given the nature of the device as a radio access point, the impact is focused on the availability of cellular services. There is no patch available for this vulnerability, and as of the reporting date, no active exploitation in the wild has been confirmed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eMinimize exposure of control system devices by ensuring the eNodeB management interfaces are not accessible from the public internet.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation by placing remote devices behind firewalls and isolating them from internal business networks.\u003c/li\u003e\n\u003cli\u003eUtilize encrypted VPN tunnels for all remote management access to the eNodeB infrastructure.\u003c/li\u003e\n\u003cli\u003eReview internal incident response procedures for handling localized denial-of-service events related to radio access network infrastructure.\u003c/li\u003e\n\u003cli\u003eContact Baicells customer support for further information regarding potential configuration workarounds, as no firmware update is planned.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-29T16:24:50Z","date_published":"2026-09-29T16:24:50Z","id":"https://feed.craftedsignal.io/briefs/2026-09-baicells-nova-430h-dos/","summary":"An unauthenticated attacker within radio range can trigger a denial-of-service on the Baicells Nova 430H eNodeB by sending malformed NAS payloads during connection setup (CVE-2026-96274).","title":"Denial-of-Service Vulnerability in Baicells Nova 430H eNodeB","url":"https://feed.craftedsignal.io/briefs/2026-09-baicells-nova-430h-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Baicells Technologies","version":"https://jsonfeed.org/version/1.1"}