OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-96274

HIGH · CVSS 7.4 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The Baicells Nova 430H is vulnerable to a denial-of-service attack due to improper validation of malformed uplink messages from unauthenticated devices within radio range. This flaw allows an attacker to disrupt service by causing the eNodeB to shut down its signaling association with the core network, leading to temporary connectivity loss. Network operators and administrators using this equipment should prioritize addressing this vulnerability to maintain service reliability and security.

CVE
CVE-2026-96274
Severity
HIGH
CVSS
7.4
EPSS
0.16%

Original NVD Description

In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during connection setup that contains an invalid NAS payload. Because the eNodeB does not properly validate this payload, it forwards the message to the core network, which can trigger a shutdown of the signaling association for the cell. This results in a temporary service disruption until the eNodeB and core network re-establish connectivity.