CISA Identified Vulnerability in Baicells Nova Hardware

The cybersecurity agency issued an advisory regarding a denial-of-service risk in certain Baicells eNodeB hardware.

Updated on Sept. 29, 2026 in Cybersecurity

Bold flat-color editorial illustration of an industrial radio unit on a mast, representing a cybersecurity advisory for telecom infrastructure.
CISA issued a security advisory identifying a denial-of-service vulnerability in Baicells Nova 430H hardware that could disrupt network communications infrastructure. AI Illustration. Upload story photo >

Live Poll

Should organizations prioritize proactive security patching for their industrial control equipment?

CISA has identified a security vulnerability affecting the Baicells Nova 430H eNodeB hardware. The flaw allows attackers to inject malformed messages and trigger a denial-of-service condition.

Why it matters

Identifying these flaws is essential for maintaining secure communications infrastructure. Addressing such vulnerabilities prevents potential system outages in networks relying on this hardware.

The vulnerability, identified as CVE-2026-96274, impacts the Baicells Nova 430H eNodeB model pBS3101SH running firmware version BaiBLQ_3.0.12 or earlier. This hardware defect is susceptible to message injection that leads to a denial-of-service.

The players

CISA

The Cybersecurity and Infrastructure Security Agency is a United States federal agency that oversees the protection of critical national infrastructure from cyber and physical threats.

Baicells

Baicells is a global provider of small cell wireless equipment, including LTE and 5G solutions, headquartered in the United States.

Qiqing Huang

Qiqing Huang is the researcher who officially reported the vulnerability to CISA.

The details

Attackers can exploit the vulnerability by injecting malformed messages into the system to induce a denial-of-service state. The issue is not exploitable remotely, and there are currently no reports of public exploitation.

Timeline

  1. September 29, 2026: CISA released the initial security advisory.

The Tech Race

This disclosure highlights the ongoing challenges in securing critical infrastructure hardware against local exploitation. It mirrors established industry patterns where researchers collaborate with federal agencies to mitigate denial-of-service risks in telecommunications gear.

Network administrators managing Baicells Nova 430H hardware should monitor for manufacturer updates to address this vulnerability. Because the flaw requires physical access to exploit, onsite security measures remain a primary defense for affected hardware.

The takeaway

Security professionals should prioritize auditing hardware firmware versions to ensure all devices are running current software. Maintaining strict physical access controls is a critical step in preventing exploitation of this specific vulnerability.

Further reading

For more on how federal agencies track and disclose hardware flaws, visit the Cybersecurity section.

Source note: This article includes information reported by Cisa.

Live Poll

Should organizations prioritize proactive security patching for their industrial control equipment?