CISA alerts on Baicells Nova 430H eNodeB vulnerability CVE-2026-96274
Operators of Baicells Nova 430H eNodeB (model pBS3101SH) running firmware BaiBLQ_3.0.12 or earlier must address the CVE-2026-96274 flaw.

On 2026-09-29 CISA issued an advisory for Baicells Nova 430H eNodeB (model pBS3101SH) firmware versions up to BaiBLQ_3.0.12. The notice identifies CVE-2026-96274, a vulnerability with a CVSS v3 score of 7.4 that affects communications and information technology critical infrastructure sectors worldwide.
The flaw allows an unauthenticated device within radio range to transmit a malformed uplink message containing an invalid NAS payload during connection setup. Because the eNodeB does not properly validate the payload, it forwards the message to the core network, which can trigger a shutdown of the signaling association for the cell, resulting in a temporary denial-of-service condition until connectivity is re-established.
CISA recommends that affected operators minimize network exposure for control system devices, place eNodeBs behind firewalls, and isolate them from business networks. When remote access is required, organizations should employ up-to-date VPN solutions and conduct impact analyses before implementing defensive measures. Additional mitigation guidance is available on the CISA Industrial Control Systems webpage and in the technical information paper ICS-TIP-12-146-01B.
The advisory notes that the vulnerability is not exploitable remotely and that no public exploitation has been reported. Organizations observing suspicious activity should follow internal procedures and report findings to CISA for tracking and correlation.
CISA also advises users to guard against social-engineering attacks by avoiding unsolicited links and attachments, and to consult CISA resources on email scams and phishing for further protection.
Further reading


