CVE-2026-77853
OS Command Injection via NETCONF M-Plane in FF-RFI079I4 / FF-RFI078I4
CVE-2026-77853 is an OS command injection flaw (CWE-78) in the FF-RFI079I4 and FF-RFI078I4 radio units, devices whose M-Plane management interface uses NETCONF (the O-RAN-style management plane). A user who can authenticate to the product's M-Plane can submit input containing unneutralized special elements that gets passed to OS commands, allowing arbitrary command execution on the device. Successful exploitation gives the attacker full control of the unit's operating system, with high impact on its confidentiality, integrity, and availability (CVSS 4.0: 8.7), though only the device itself is affected, not other systems. Operators that deploy these specific models and expose NETCONF (typically TCP 830) to users beyond trusted management staff are affected. There is no public proof of concept, the flaw is not in the CISA KEV catalog, and no exploitation has been reported.
What to do: Check the vendor and JPCERT/CC advisories for these model numbers and apply the patched firmware as soon as it is available. Until then, restrict NETCONF (TCP 830) M-Plane access to a dedicated management network with an IP allowlist, rotate M-Plane credentials, and disable any unnecessary management accounts. Review device and NETCONF server logs for unexpected or malformed commands indicating injection attempts.
| FF-RFI079I4 | — |
| FF-RFI078I4 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.