Skip to content
Rota Nacional

Cyber ·

Baicells Nova 430H flaw may temporarily disrupt cellular service

A CISA advisory published on September 29, 2026 describes a denial-of-service flaw in the Nova 430H eNodeB. The notice says no fix is planned and recommends reducing device exposure.

CISA advisory ICSA-26-272-04, published on September 29, 2026, covers the Baicells Nova 430H eNodeB, model pBS3101SH. The flaw, CVE-2026-96274, received high scores: 7.4 under CVSS 3.1 and 8.3 under CVSS 4.0. The advisory covers communications and information technology and says the equipment is deployed worldwide.

According to the notice, an unauthenticated device within radio range can send a malformed uplink message with an invalid NAS payload during connection setup. Incorrect validation lets the eNodeB forward the message to the core network. This can terminate the cell's signaling association and temporarily interrupt service until the eNodeB and core network restore connectivity. The flaw is classified as CWE-248, uncaught exception.

CISA says Baicells did not respond to requests to collaborate and that no fix is planned. It recommends minimizing network exposure, keeping devices and control systems off the public internet, placing control networks and remote devices behind firewalls, and using updated VPNs when remote access is needed. The agency cautions that VPNs can also have vulnerabilities and depend on the security of connected devices. Assess risks and impacts before applying defensive measures; contact Baicells support for further information.

To check the scope, scores, and recommendations, consult the original CISA advisory ICSA-26-272-04 and its CSAF summary, and search for CVE-2026-96274. The source text is an automatic translation of content from the CISA feed; verify details in the advisory.

Get new articles

Privacy, AI engineering and security in your inbox.

Rota Nacional

Bring privacy into your workflow.

30 days, no card, with a starting quota. After that, Pix credit from R$ 5,00.

Try free