How can operators check whether a Baicells Nova 430H eNodeB is running an affected version up to BaiBLQ_3.0.12?

If you operate a Baicells Nova 430H, the first practical question is simple: does your unit match the affected model and software version named by CISA?
Check the model and version named in the advisory
CISA identifies the affected device as:
| Item to verify | Affected value |
|---|---|
| Product | Baicells Nova 430H eNodeB |
| Model | pBS3101SH |
| Affected versions | Up to and including BaiBLQ_3.0.12 |
| Vulnerability | CVE-2026-96274 |
So the check is not just “Do we use a Nova 430H?” It is “Do we use Nova 430H eNodeB model pBS3101SH, and is it running BaiBLQ_3.0.12 or an earlier version?”
What operators can confirm from the CISA notice
The advisory confirms that pBS3101SH versions up to and including BaiBLQ_3.0.12 are affected. It does not provide, in the context here, a step-by-step device menu path or command for finding the installed software version.
That means operators should verify the model and firmware or software version through their normal device management records, administration interface, or vendor-maintenance process, then compare that value against the CISA affected-version line.
Why this check matters
CISA says CVE-2026-96274 could allow malformed messages to cause a denial-of-service condition. The described scenario involves an unauthenticated device in radio range sending an invalid NAS payload during connection setup.
If your device is not pBS3101SH, or is not running a version up to BaiBLQ_3.0.12, this specific affected-version statement may not apply in the same way. If it does match, check the official advisory for the latest vendor and mitigation details before making operational changes.
What should a network operator do if a Nova 430H temporarily loses service after malformed NAS payload activity?

A temporary service loss on a Nova 430H after suspected malformed NAS payload activity should be handled as a service-disruption event tied to the behavior CISA described.
The direct response: confirm reconnect status
CISA says exploitation may temporarily disrupt service until the eNodeB and core network reconnect. Based on that, the immediate practical check is whether the eNodeB and the core network have reconnected after the disruption.
The advisory context does not give a detailed recovery runbook, restart sequence, or vendor command. So the safest answer is narrow: verify the reconnect state using your normal network operations tools and device-management process, then preserve enough information to compare what happened with the CISA scenario.
What to look for
The advisory describes this chain:
| Point | What CISA confirms |
|---|---|
| Trigger | An invalid NAS payload during connection setup |
| Access condition | An unauthenticated device in radio range |
| Result | Temporary denial-of-service condition |
| Recovery condition described | Service disruption lasts until the eNodeB and core network reconnect |
If those elements match what operators observe, CVE-2026-96274 should be considered relevant to the incident review.
What not to assume
The context does not confirm a permanent outage, data compromise, or a specific fix procedure. It also does not provide a confirmed patch version in the supplied facts.
Because advisory details can be updated, operators should check CISA’s official page before deciding that their response notes or mitigation plan are complete.
What changed in the September 29, 2026 CISA advisory for Baicells Nova 430H?

CISA’s September 29, 2026 advisory added a specific cybersecurity notice for the Baicells Nova 430H involving a denial-of-service issue.
What the advisory identifies
The advisory names the issue as CVE-2026-96274 and gives it a CVSS v3 score of 7.4.
It also identifies the affected product line in a specific way: Baicells Nova 430H eNodeB model pBS3101SH, for versions up to and including BaiBLQ_3.0.12.
The attack scenario CISA describes
CISA describes a case where an unauthenticated device in radio range sends an invalid NAS payload during connection setup. That malformed message activity may cause a denial-of-service condition.
The disruption described in the context is temporary: service may be affected until the eNodeB and core network reconnect.
What readers should take from the September 29 notice
The main practical change is that operators now have a named CVE, a severity score, an affected model and version range, and a described radio-range exploitation scenario to compare against their own environment.
The supplied context does not include broader mitigation details, so the official CISA advisory is the place to check for any later updates.
Who is exposed to the Nova 430H CVE-2026-96274 issue based on radio-range access?

Exposure to CVE-2026-96274 depends on both the affected device/version and the radio-range scenario CISA describes.
Who should check exposure
Operators should check their environment if they use:
| Exposure factor | CISA-confirmed detail |
|---|---|
| Device | Baicells Nova 430H eNodeB |
| Model | pBS3101SH |
| Version range | Up to and including BaiBLQ_3.0.12 |
| Scenario | An unauthenticated device in radio range sends an invalid NAS payload during connection setup |
In plain terms: if an affected Nova 430H pBS3101SH is reachable in the radio-range scenario CISA describes, it is the kind of setup this advisory is about.
What “radio range” means for this question
The key point is that CISA’s scenario does not require the device sending the invalid NAS payload to be authenticated. The source context says the device is in radio range and sends the malformed payload during connection setup.
The context does not define a distance, coverage radius, or site-specific exposure calculation. Operators should not invent one from the advisory summary alone.
What the issue can do
CISA says exploitation could disrupt service temporarily. The disruption may last until the eNodeB and core network reconnect.
For the most current exposure and mitigation details, use the official CISA advisory rather than relying only on a summary.
Sources / Learn more
Related reading
- How can lwIP users determine whether their MQTT Client Application version is vulnerable?; What should teams do to update affected lwIP MQTT Client Application deployments?; How does CVE-2026-87121 change the risk profile for devices using the lwIP MQTT Client Application?
- How can teams determine whether their SIMOVE Fleetmanager or SIPLANT version is affected by CVE-2026-67367?; What should Siemens SIMOVE Fleetmanager and SIPLANT users do after the September 22, 2026 CISA advisory?; What could the path traversal vulnerability allow an attacker to access?; Which SIMOVE Fleetmanager versions are listed as affected before the fixed releases?
- How do Siemens WTV676 and WTV776 operators check whether their Web Interface version is affected?; What should operators do if a Siemens WTV676 or WTV776 device enters protection mode and Web Access stops working?; Which Siemens WTV676 and WTV776 updates address the CISA denial of service advisory?
- How can a programmatic user access the Federal Register or eCFR material for this FCC docket?; What should a human user do if the Federal Register page for this FCC docket shows a CAPTCHA notice?
![[Baicells Nova 430H]: Baicells Nova 430H CVE-2026-96274: Affected Versions, Exposure, and Response](https://trendingissue.blog/wp-content/uploads/2026/10/pexels-1626638.jpg)