Unauthenticated Message Handling Flaw in Baicells Nova 430H by Baicells
CVE-2026-96274
8.3HIGH
What is CVE-2026-96274?
The Baicells Nova 430H is susceptible to an issue where an unauthenticated device within radio range can transmit a malformed uplink message during connection setup. This message contains an invalid NAS payload that the eNodeB fails to properly validate. Consequently, the malformed message is forwarded to the core network, potentially causing a disruption by shutting down the signaling association for the cell. This vulnerability can lead to temporary service outages until connectivity is re-established between the eNodeB and the core network.
Affected Version(s)
Nova 430H eNodeB (model pBS3101SH) 0
References
CVSS V4
Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Qiqing Huang reported this vulnerability to CISA.
