Description
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.
Published: 2026-09-15
Score: 8.7 High
EPSS: 1.9% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A flaw in the handling of OS commands within the Lite‑On FF‑RFI078I4 and FF‑RFI079I4 devices allows an authenticated user on the NETCONF M‑Plane interface to inject shell commands. Because the commands run with device privileges, an attacker can tamper with device configuration, exfiltrate sensitive data, or install persistent malware. The vulnerability is an OS command injection (CWE‑78).

Affected Systems

The affected products are Lite‑On Technology Corporation’s FF‑RFI078I4 and FF‑RFI079I4 models, which are typically deployed for 5G network management. No additional version range is specified beyond the product identifiers.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity, and the EPSS score of 1% shows a low but nonzero likelihood of exploitation in the near term. The vulnerability is not listed in CISA’s KEV catalog, but the combination of high impact and authenticated access means it should be treated as a critical risk. Attackers would need legitimate login credentials; once logged in, they can run arbitrary commands, leading to complete compromise of the device.

Generated by OpenCVE AI on September 17, 2026 at 18:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware update from Lite‑On that addresses the OS command injection in FF‑RFI079I4 and FF‑RFI078I4
  • Restrict M‑Plane interface access to approved IP ranges and enable multi‑factor authentication to limit the attacker’s ability to login
  • Disable or isolate the M‑Plane interface on devices that do not require remote configuration and monitor logs for suspicious command injection attempts

Generated by OpenCVE AI on September 17, 2026 at 18:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection via NETCONF in Lite‑On FlexFi Devices

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Lite-on Technology Corporation
Lite-on Technology Corporation ff-rfi078i4
Lite-on Technology Corporation ff-rfi079i4
Vendors & Products Lite-on Technology Corporation
Lite-on Technology Corporation ff-rfi078i4
Lite-on Technology Corporation ff-rfi079i4

Wed, 16 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title OS Command Injection via NETCONF in Lite‑On FlexFi Devices

Tue, 15 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.
Weaknesses CWE-78
References
Metrics cvssV3_0

{'score': 8.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Lite-on Technology Corporation Ff-rfi078i4 Ff-rfi079i4
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-15T13:31:40.999Z

Reserved: 2026-09-07T08:29:54.584Z

Link: CVE-2026-77853

cve-icon Vulnrichment

Updated: 2026-09-15T13:31:33.012Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T09:16:44.067

Modified: 2026-09-16T19:27:25.623

Link: CVE-2026-77853

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')