logo

Baicells: A Retrospective

ID: 35929ea0-50a3-5668-b0b8-0879ca4bd3cc

STIX ID: report--35929ea0-50a3-5668-b0b8-0879ca4bd3cc

Feed Name: Censys Blog

Threat Score
70/100

Date Published: 2025-01-30

Date Updated: 2026-04-27

Author: Jean Pierre Ruiz Ocampo; The Censys Research Team

...
...

Censys investigated Baicells telecom devices after Reuters asked for host counts and produced a public, technical analysis showing many internet-exposed Baicells eNodeB and router devices, fingerprinting methods to enumerate models/firmware, confirmed instances of QRTB firmware vulnerable to CVE-2023-0776 and RTS firmware issues tied to CVE-2023-24508 (including a likely pre-auth remote-code-execution vector via run_commands.sh and disabled session validation), and flagged default VPN/CloudEPC connections to China-based endpoints; the team found vulnerable hosts (28 confirmed QRTB responses and hundreds of devices publicly reachable) but did not identify confirmed active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.