Description
In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during connection setup that contains an invalid NAS payload. Because the eNodeB does not properly validate this payload, it forwards the message to the core network, which can trigger a shutdown of the signaling association for the cell. This results in a temporary service disruption until the eNodeB and core network re-establish connectivity.
Published: 2026-09-29
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: Denial of Service / Service Disruption
Action: Assess Impact
AI Analysis

Impact

An unauthenticated device within radio range can send a malformed uplink message during connection setup that contains an invalid NAS payload. Because the eNodeB fails to validate the payload, it forwards the message to the core network. The core network may shutdown the signaling association for the cell, causing a temporary service disruption until connectivity is reestablished with the eNodeB and core network.

Affected Systems

Baicells Nova 430H eNodeB (model pBS3101SH). No specific firmware version is indicated in the advisory.

Risk and Exploitability

The vulnerability is assessed with a CVSS score of 8.3, indicating a high severity risk. Exploit probability data (EPSS) is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is over the air, as any unauthenticated device within radio range can trigger the malformed uplink message. Because the eNodeB lacks proper payload validation, the attack does not require privileged access or additional credentials, underscoring the high risk of service interruption.

Generated by OpenCVE AI on September 29, 2026 at 21:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Baicells firmware upgrade that corrects NAS payload validation; if no update is available, request vendor support.
  • Configure the eNodeB or apply a temporary firewall rule to reject any uplink messages from devices that have not completed authentication during connection setup.
  • Enable core‑network monitoring and alerts for sudden signaling association shutdowns so that incidents can be identified and responded to quickly until a permanent fix is applied.

Generated by OpenCVE AI on September 29, 2026 at 21:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during connection setup that contains an invalid NAS payload. Because the eNodeB does not properly validate this payload, it forwards the message to the core network, which can trigger a shutdown of the signaling association for the cell. This results in a temporary service disruption until the eNodeB and core network re-establish connectivity.
Title Uncaught exception in Baicells Nova 430H
Weaknesses CWE-248
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-09-29T21:01:58.604Z

Reserved: 2026-09-22T20:38:24.656Z

Link: CVE-2026-96274

cve-icon Vulnrichment

Updated: 2026-09-29T20:59:56.270Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T20:17:31.610

Modified: 2026-09-29T22:19:05.720

Link: CVE-2026-96274

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T21:45:17Z

Weaknesses