Baicells develops a focused line of cellular-access products spanning small-cell base stations and related firmware, including the Neutrino and Nova series, that serve as critical infrastructure in distributed wireless deployments. The vendor's disclosed vulnerabilities concentrate on application and configuration weaknesses endemic to web-facing network appliances: cross-site scripting, command injection, hard-coded credentials, improper access control, and code injection, reflecting the input-handling and authentication demands of management interfaces on deployed infrastructure; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Baicells over time
Of all the CVEs published by Baicells as a CNA, 80.0% affect products that Baicells develops as a vendor.
Of all the CVEs published that affect products developed by Baicells, 80.0% are self-published by Baicells as a CNA.
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24693CRITICAL Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by remote attackers to authentica | Mar 30, 2022 | 9.8 | 33 | NO | NO |
CVE-2023-24022CRITICAL Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB devices with firmware through RTS/RTD 3.7.11.3 have hardcoded credentials that are easily discovered and can be used by rem | Jan 26, 2023 | 9.8 | 32 | NO | NO |
CVE-2023-24508CRITICAL Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB and Nova 246 devices with firmware through RTS/RTD 3.6.6 are vulnerable to remote shell code exploitation via HTTP command | Jan 26, 2023 | 9.6 | 30 | NO | NO |
CVE-2023-1097CRITICAL Baicells EG7035-M11 devices with firmware through BCE-ODU-1.0.8 are vulnerable to improper code exploitation via HTTP GET command injections. Commands are executed using pre-login | Mar 1, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-0776CRITICAL Baicells Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430 LTE TDD eNodeB devices with firmware through QRTB 2.12.7 are vulnerable to remote shell code exploitation via HTTP comman | Feb 11, 2023 | 10.0 | 29 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Baicells.
Media articles that mention a CVE ID that affects a product developed by Baicells — matched by CVE ID, not by vendor name.