Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Unauthenticated Radio‑Range Attack Triggers DoS in Baicells Nova 430H eNodeB (CVE‑2026‑96274)

A CVE‑2026‑96274 flaw in Baicells Nova 430H eNodeB allows an unauthenticated device within radio range to send malformed NAS payloads that shut down signaling, causing temporary service loss. The issue underscores the importance of continuous control monitoring and auditable evidence for telecom operators facing regulatory scrutiny.

LiveThreat™ Intelligence · 📅 September 29, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
5 recommended
📰
Source
cisa.gov

Unauthenticated Radio‑Range DoS in Baicells Nova 430H eNodeB (CVE‑2026‑96274)

What It Is — Baicells Nova 430H eNodeB (model pBS3101SH) versions ≤ BaiBLQ_3.0.12 contain an unauthenticated input validation flaw (CVE‑2026‑96274). An attacker within radio range can send a malformed uplink message with an invalid NAS payload, which the eNodeB forwards to the core network, causing a signaling shutdown and temporary service outage.

Exploitability — The vulnerability is publicly disclosed, has a CVSS v3 base score of 7.4 (High), and can be exploited without credentials or prior access. No vendor‑issued fix is currently available.

Affected Products — Baicells Technologies – Nova 430H eNodeB (model pBS3101SH) firmware ≤ BaiBLQ_3.0.12.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for continuous validation of third‑party equipment against security baselines; evidence of such validation is a core control‑assurance artifact.
  • Highlights gaps in network‑level monitoring: without telemetry that flags malformed NAS payloads, organizations lack defensible evidence of timely detection.
  • Forces telecom operators to document vendor‑risk mitigation (e.g., segmentation, fallback procedures) to satisfy audit expectations across frameworks that map to the “Network Security” control objective.

Recommended Actions

  • Inventory all deployed Nova 430H units and verify firmware versions.
  • Apply any interim mitigations (e.g., radio‑range access controls, strict ACLs) while awaiting a vendor patch.
  • Deploy IDS/IPS rules that detect abnormal NAS payloads and generate alerts for rapid incident response.
  • Document the risk in your third‑party risk register and capture remediation evidence for audit trails.
  • Engage Baicells directly for a remediation timeline and consider alternative equipment if a fix is not forthcoming.

Source: CISA Advisory – ICSA‑26‑272‑04

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-272-04 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →