Impact
A command injection flaw exists in the LuCI Web Interface of the Baicells EG3661M router (BaiCE_BQ6_2.0.5.3_NA). The vulnerability allows an attacker to manipulate arguments for MaxHops, Timeout, or Size in /cgi-bin/luci, resulting in arbitrary OS command execution. This flaw can compromise the confidentiality, integrity, and availability of the device and the network it serves.
Affected Systems
The affected product is the Baicells EG3661M router running firmware version BaiCE_BQ6_2.0.5.3_NA. No other vendors or product variants are listed.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. EPSS data is not available, but the vulnerability is publicly documented and exploits have been shared online, implying a realistic threat of exploitation. The tool is accessible via the web interface, making the attack vector remote. The vulnerability is not yet listed in the CISA KEV catalog.
OpenCVE Enrichment