Skip to content
Security & Trust

CISA lists no fix for a Baicells cell radio flaw; vendor did not reply to CISA

CISA says Baicells has not responded to its requests to work together on mitigating a bug in the Nova 430H.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
CISA lists no fix for a Baicells cell radio flaw; vendor did not reply to CISA

AI-generated image for WebPulse. About our images

Key finding

Fix status: No fix planned (Source: CISA advisory ICSA-26-272-04 (September 29, 2026))

A patch needs a vendor to show up

Advisories usually point to a patch or update. This one ends with a blank. CISA, the US cyber agency, published an advisory on September 29 for the Baicells Nova 430H, a cell radio unit known as an eNodeB. CISA lists the fix status as "No fix planned."

The reason CISA gives is narrow. Baicells has not responded to CISA's requests to work together on a mitigation. That is silence toward CISA, not an announcement. The advisory does not say Baicells has refused to patch. It does not say whether Baicells has made any other statement, and it does not rule out that a fix exists outside CISA's process.

For anyone who owns or relies on this device, the question changes. It is no longer how fast the vendor will patch. It is what you do while CISA lists no fix and Baicells has not responded to its requests.

No fix planned
Fix status
Source: CISA advisory ICSA-26-272-04 (September 29, 2026)

How the flaw works

The advisory tracks the flaw as CVE-2026-96274. It affects the Nova 430H eNodeB, model pBS3101SH, in firmware version BaiBLQ_3.0.12 and earlier.

A cell radio like this sits between phones or devices and the operator's core network. When a device connects, it sends setup messages. Some carry a NAS payload, which is signaling data meant for the core network rather than for the radio itself.

Here is the attack path CISA describes. A device that has not logged in or proven anything, but is close enough to reach the radio, sends a broken setup message. Its NAS payload is invalid. The Nova 430H fails to check it and passes it on to the core network.

That can shut down the signaling association for the cell. This is the link the radio and core network use to coordinate. Service is disrupted until the two sides reconnect. CISA describes the disruption as temporary.

CISA classifies the weakness as CWE-248, an uncaught exception. In plain terms, the system meets input it did not expect and fails instead of rejecting it.

BaiBLQ_3.0.12 and earlier
Affected firmware
Source: CISA advisory ICSA-26-272-04 (September 29, 2026)

What limits the risk, and what does not

The limits are real. CISA states the vulnerability is not exploitable remotely. The attacker must be within radio range of the cell. CISA also says it has received no reports of public exploitation targeting this flaw.

None known
Public exploitation reported to CISA
Source: CISA advisory ICSA-26-272-04 (September 29, 2026)

The advisory also does not describe data theft or control of the device. The stated impact is denial of service.

Still, the design lesson is worth a manager's attention. The edge device trusted input from someone who had proven nothing. It then handed that input to a shared part of the network. The attacker needs no login. Only the vendor can add the missing check.

The larger problem is the missing reply

Owners can limit exposure, but they cannot repair the missing validation themselves. That depends on the vendor. According to the advisory, Baicells has not responded to CISA's requests to work with it on mitigation. The advisory only invites users to contact Baicells customer support for more information.

Researcher Qiqing Huang reported the flaw to CISA. The advisory lists Baicells' headquarters as United States and the affected sectors as Communications and Information Technology.

This is a supplier-risk problem, not only a technical one. A product with no available fix carries a different risk than one that gets patched in a month. Based on the advisory, owners cannot tell which of the two they have.

What leaders should ask

CISA's general guidance for control-system devices is to keep them off the internet and behind firewalls, and to update any VPNs used for remote access. That helps with remote exposure. It does not stop someone within radio range, so treat it as partial cover for this flaw.

Put these questions to your network and procurement teams:

1. Do we run, or does a provider we depend on run, Nova 430H units? Which firmware version is on each?

2. Has anyone contacted Baicells support, as CISA suggests? Did the company say whether a fix is coming?

3. Where are these radios physically placed, and who can get within range of them?

4. What does a signaling outage cost us, and how quickly does service return on its own?

5. Do our contracts give us any recourse when a vendor does not respond? Do we have a replacement plan?

How a vendor responds when a flaw is reported is part of the product, just like its firmware. This advisory is a reminder to check for it before the day you need it.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: CISA.

CVEs in this analysis
CVE-2026-96274
Share this insight