CVE-2023-24508
Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB and Nova 246 devices with firmware through RTS/RTD 3.6.6 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods below have been tested and validated by a 3rd party analyst and has been confirmed exploitable special thanks to Rustam Amin for providing the steps to reproduce.
Published:Jan 24, 2023
Last Modified:Mar 27, 2025
EPS:Jan 24, 2023
EPSS Score:0.00191
CVSS Score:8.1
Affected Products
Vendor
Product
Action
Vendor
Baicells
Product
Nova227
Baicells
Nova227
Vendor
Baicells
Product
Nova233
Baicells
Nova233
Vendor
Baicells
Product
Nova243
Baicells
Nova243
Vendor
Baicells
Product
Nova246
Baicells
Nova246
Vendor
Baicells
Product
Rtd Firmware
Baicells
Rtd Firmware
Vendor
Baicells
Product
Rts Firmware
Baicells
Rts Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
