CVE Feed

    Dashboard / CVE / CVE-2023-24508

    CVE-2023-24508

    Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB and Nova 246 devices with firmware through RTS/RTD 3.6.6 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods below have been tested and validated by a 3rd party analyst and has been confirmed exploitable special thanks to Rustam Amin for providing the steps to reproduce. 

    Published:Jan 24, 2023
    Last Modified:Mar 27, 2025
    EPS:Jan 24, 2023
    EPSS Score:0.00191
    CVSS Score:8.1

    Affected Products

    Vendor
    Baicells
    Product
    Nova227
    Vendor
    Baicells
    Product
    Nova233
    Vendor
    Baicells
    Product
    Nova243
    Vendor
    Baicells
    Product
    Nova246
    Vendor
    Baicells
    Product
    Rtd Firmware
    Vendor
    Baicells
    Product
    Rts Firmware

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High