CISA Identified Vulnerability in Baicells Hardware

A newly disclosed flaw in the Baicells Nova 430H allows attackers to trigger a denial-of-service condition.

Updated on Sept. 29, 2026 in Cybersecurity

Bold flat-color editorial illustration showing a stylized rectangular radio base station unit mounted on a wall, navy blue and cream.
CISA has issued an advisory for the Baicells Nova 430H eNodeB, identifying a vulnerability that allows for remote denial-of-service attacks. AI Illustration. Upload story photo >

Live Poll

Should organizations prioritize proactive security patching for their industrial control equipment?

CISA has issued an advisory regarding CVE-2026-96274, a vulnerability found in the Baicells Nova 430H eNodeB hardware. The flaw, which affects devices running software version BaiBLQ_3.0.12 or earlier, can be leveraged to force a denial-of-service state.

Why it matters

The vulnerability poses a risk to critical telecommunications infrastructure that relies on these units for connectivity. Because the flaw allows for service disruption, identifying the affected hardware ensures operators can mitigate potential network outages.

The vulnerability, tracked as CVE-2026-96274, impacts the Baicells Nova 430H eNodeB model pBS3101SH. It is not currently exploitable remotely.

The players

CISA

The Cybersecurity and Infrastructure Security Agency is a United States federal agency responsible for overseeing national cyber defense and infrastructure protection.

Baicells

A global manufacturer specializing in small cell wireless infrastructure and LTE/5G hardware solutions.

Qiqing Huang

The security researcher who reported the vulnerability to CISA.

The details

The flaw enables attackers to inject malformed messages directly into the system, which triggers a denial-of-service condition where the device stops processing traffic. The eNodeB—an Evolved Node B, which functions as the primary radio component in LTE cellular networks—becomes unresponsive once this specific command sequence is processed. No public exploitation of this vulnerability has been reported at this time.

Timeline

  1. September 29, 2026: CISA released the initial security advisory.

The Tech Race

This disclosure highlights the ongoing effort to harden telecommunications hardware against local attack vectors. It follows the established patterns set by the CISA Known Exploited Vulnerabilities Catalog for surfacing flaws in critical networking gear.

Network operators and infrastructure managers should audit their deployments of the Baicells Nova 430H pBS3101SH to confirm their software version status. While remote exploitation is not possible, local network security should be prioritized until firmware updates are applied.

The takeaway

The security of cellular infrastructure depends on timely patching of individual hardware nodes like the Nova 430H. Watch for upcoming firmware release notes from Baicells to address the identified version deficiency.

Further reading

For additional context on protecting network infrastructure, visit our Cybersecurity section.

Source note: This article includes information reported by Cisa.

Live Poll

Should organizations prioritize proactive security patching for their industrial control equipment?