Baicells: A Retrospective
ID: 35929ea0-50a3-5668-b0b8-0879ca4bd3cc
STIX ID: report--35929ea0-50a3-5668-b0b8-0879ca4bd3cc
Feed Name: Censys Blog
Date Published: 2025-01-30
Date Updated: 2026-04-27
Author: Jean Pierre Ruiz Ocampo; The Censys Research Team
Censys investigated Baicells telecom devices after Reuters asked for host counts and produced a public, technical analysis showing many internet-exposed Baicells eNodeB and router devices, fingerprinting methods to enumerate models/firmware, confirmed instances of QRTB firmware vulnerable to CVE-2023-0776 and RTS firmware issues tied to CVE-2023-24508 (including a likely pre-auth remote-code-execution vector via run_commands.sh and disabled session validation), and flagged default VPN/CloudEPC connections to China-based endpoints; the team found vulnerable hosts (28 confirmed QRTB responses and hundreds of devices publicly reachable) but did not identify confirmed active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
