Unauthenticated Message Handling Flaw in Baicells Nova 430H by Baicells
CVE-2026-96274

8.3HIGH

Key Information:

Vendor

Baicells

Vendor
CVE Published:
29 September 2026

What is CVE-2026-96274?

The Baicells Nova 430H is susceptible to an issue where an unauthenticated device within radio range can transmit a malformed uplink message during connection setup. This message contains an invalid NAS payload that the eNodeB fails to properly validate. Consequently, the malformed message is forwarded to the core network, potentially causing a disruption by shutting down the signaling association for the cell. This vulnerability can lead to temporary service outages until connectivity is re-established between the eNodeB and the core network.

Affected Version(s)

Nova 430H eNodeB (model pBS3101SH) 0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Qiqing Huang reported this vulnerability to CISA.
.