ZeroHour

CVE-2026-77853

OS Command Injection via NETCONF M-Plane in FF-RFI079I4 / FF-RFI078I4

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-77853 is an OS command injection flaw (CWE-78) in the FF-RFI079I4 and FF-RFI078I4 radio units, devices whose M-Plane management interface uses NETCONF (the O-RAN-style management plane). A user who can authenticate to the product's M-Plane can submit input containing unneutralized special elements that gets passed to OS commands, allowing arbitrary command execution on the device. Successful exploitation gives the attacker full control of the unit's operating system, with high impact on its confidentiality, integrity, and availability (CVSS 4.0: 8.7), though only the device itself is affected, not other systems. Operators that deploy these specific models and expose NETCONF (typically TCP 830) to users beyond trusted management staff are affected. There is no public proof of concept, the flaw is not in the CISA KEV catalog, and no exploitation has been reported.

What to do: Check the vendor and JPCERT/CC advisories for these model numbers and apply the patched firmware as soon as it is available. Until then, restrict NETCONF (TCP 830) M-Plane access to a dedicated management network with an IP allowlist, rotate M-Plane credentials, and disable any unnecessary management accounts. Review device and NETCONF server logs for unexpected or malformed commands indicating injection attempts.

Affected
FF-RFI079I4
FF-RFI078I4
Estimated exposure
unknown; likely limited to carrier/private-network RAN deployments of these two models — No public active-install counts or internet-scan figures exist for these carrier radio units, and NETCONF M-Plane access is normally confined to private operator management networks rather than the open internet, so a defensible number…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.

Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.