CVE-2026-80217
nicheHidden Functionality Allows OS Command Execution in FF-RFI079I4 / FF-RFI078I4
A hidden functionality flaw (CWE-912) in the FF-RFI079I4 and FF-RFI078I4 devices allows a user who can log in over SSH and reach the device's enable mode to execute arbitrary operating-system commands. This is not an unauthenticated remote attack — exploitation requires valid SSH credentials and access to the privileged enable mode, so it abuses undocumented functionality reachable from the authenticated CLI rather than a memory-safety bug. A successful attacker gains the ability to run any OS command on the device, with high impact on its confidentiality, integrity, and availability (CVSS v4.0 8.7, high, PR:L). Any organization running either model — especially with SSH reachable from untrusted networks or with shared/default administrative credentials — is affected. No public proof of concept is known, the issue is not on the CISA KEV list, and there is no evidence of exploitation in the wild.
What to do: Apply the vendor's fixed firmware for FF-RFI079I4 and FF-RFI078I4 as described in the JPCERT advisory (check the vendor's support page for the specific update). Until patched, disable SSH if not needed or restrict it to trusted management networks, and rotate both login and enable-mode credentials while eliminating shared or default accounts. Review device logs for unexpected enable-mode sessions or unusual CLI activity.
| FF-RFI079I4 | — |
| FF-RFI078I4 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands.
- Weakness
- CWE-912
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.