As reported by CISA in advisory ICSA-26-272-04, a high-severity vulnerability in the Baicells Nova 430H eNodeB exposes LTE small cell deployments to denial-of-service attacks from any unauthenticated device within radio range. The flaw, tracked as CVE-2026-96274, carries a CVSS v3.1 score of 7.4 (High) and a notably higher CVSS v4.0 score of 8.3 (High) — reflecting the complete absence of attack prerequisites and the criticality of the availability impact.

Security Impact: As reported by CISA in advisory ICSA-26-272-04, a high-severity vulnerability in the Baicells Nova 430H eNodeB exposes LTE small cell deployments to denial-of-service attacks from any unauthenticated device within radio range.

Vulnerability at a Glance

FieldDetail
CVECVE-2026-96274
CVSS v3.17.4 High — AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
CVSS v4.08.3 High — AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Affected ProductBaicells Nova 430H eNodeB (model pBS3101SH), firmware ≤ BaiBLQ_3.0.12
VendorBaicells Technologies (US HQ)
CWECWE-248: Uncaught Exception
Patch StatusNo fix planned — Baicells has not responded to CISA coordination requests
Active ExploitationNot confirmed in the wild at time of advisory

Why This Matters Beyond the CVSS Score

The mechanics of this vulnerability are particularly insidious because they exploit the trust relationship between the radio access network (RAN) and the core network — not a traditional IP-based attack surface. A malformed Non-Access Stratum (NAS) payload sent during UE connection setup is forwarded by the eNodeB to the Mobility Management Entity (MME) or equivalent core component without proper validation. The uncaught exception in the core then tears down the S1 signaling association for the entire cell, not just the offending connection.

This means a single attacker with a software-defined radio and no credentials can effectively take an entire cell sector offline repeatedly. The disruption is temporary — the eNodeB and core re-establish connectivity — but an attacker can cycle this attack indefinitely, rendering the cell unusable for its service lifetime. For operators relying on Baicells Nova 430H units for rural broadband, temporary event coverage, or private LTE deployments, this is a sustained availability threat with no software remediation path.

The Vendor Non-Responsiveness Problem

Perhaps the most alarming aspect of this advisory is not the vulnerability itself — it is that Baicells "has not responded to requests to work with CISA to mitigate this vulnerability." When a vendor of critical communications infrastructure effectively abandons a known exploitable product, operators are left without a remediation path and must assume permanent exposure.

This pattern is not unique to Baicells but it is especially problematic in the small cell and private LTE market, where vendors may lack dedicated product security incident response teams (PSIRTs) or may have moved on to newer product lines. Operators must factor vendor lifecycle commitments — not just vulnerability disclosures — into their procurement risk models. A device that cannot be patched is a device that cannot be trusted in production for the remainder of its deployment.

Who Is Most at Risk

  • Rural and remote broadband ISPs leveraging Baicells small cells for last-mile LTE connectivity — a single disrupted cell can cut service to an entire community
  • Private LTE/5G network operators in industrial, utility, or enterprise settings where Baicells eNodeBs provide coverage for critical IoT or operational communications
  • Temporary event and emergency response deployments where Baicells units provide rapid cellular coverage — an attacker could disable connectivity during a planned or emergency operation
  • Deployments in physically accessible areas — since the attack requires radio proximity, rooftop or pole-mounted units in public spaces are most exposed

Shield53 Recommendations

With no vendor patch available, defenders must rely on architectural and operational compensating controls:
  • Accelerate hardware replacement planning. If your fleet includes Nova 430H (pBS3101SH) units at ≤BaiBLQ_3.0.12, begin evaluating alternative eNodeB vendors with active PSIRT programs. Assume this product line will not receive further security updates.
  • Deploy signaling firewalls or S1-U/S1-MME inspection. Where feasible, place a signaling-aware intermediary between the eNodeB and the EPC core to detect and drop malformed NAS payloads before they reach the MME. This is the most effective compensating control given the root cause.
  • Implement radio-layer monitoring. Deploy RF spectrum monitoring near critical Baicells cell sites to detect anomalous UE attach storms or repeated connection setup failures that may indicate active exploitation.
  • Physical access hardening. While the attack requires radio range rather than physical access to the device, reducing the RF footprint via directional antennas, power limiting, and site placement can reduce the effective attack radius.
  • Network segmentation and failover. Ensure that S1 signaling disruption on one eNodeB does not cascade to shared core components. Isolate signaling paths per cell site where the architecture permits.
  • Escalate through your vendor channel. If you are a Baicells customer, escalate through your account representative and contractually demand a firmware remediation commitment. CISA noted the vendor has been non-responsive — documented customer pressure is often the only lever that works.
  • Inventory and exposure mapping. Identify all Baicells eNodeB deployments in your environment, confirm firmware versions, and flag affected units in your asset risk register as permanently unpatchable.

This advisory underscores a systemic risk in the small cell ecosystem: lightweight deployment economics often come paired with lightweight security lifecycle commitments. Until the industry holds RAN vendors to the same patching expectations as traditional network equipment suppliers, operators will continue absorbing risk that properly belongs upstream.