Impact
A flaw in the handling of OS commands within the Lite‑On FF‑RFI078I4 and FF‑RFI079I4 devices allows an authenticated user on the NETCONF M‑Plane interface to inject shell commands. Because the commands run with device privileges, an attacker can tamper with device configuration, exfiltrate sensitive data, or install persistent malware. The vulnerability is an OS command injection (CWE‑78).
Affected Systems
The affected products are Lite‑On Technology Corporation’s FF‑RFI078I4 and FF‑RFI079I4 models, which are typically deployed for 5G network management. No additional version range is specified beyond the product identifiers.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity, and the EPSS score of 1% shows a low but nonzero likelihood of exploitation in the near term. The vulnerability is not listed in CISA’s KEV catalog, but the combination of high impact and authenticated access means it should be treated as a critical risk. Attackers would need legitimate login credentials; once logged in, they can run arbitrary commands, leading to complete compromise of the device.
OpenCVE Enrichment