CVE-2026-77853: Lite-On Technology Corporation Ff-RFI078I4
High severity, CVSS 8.7. EPSS: 1.9% chance of exploitation in the next 30 days.
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.
Affected products
- Lite-On Technology Corporation Ff-RFI078I4: before 02.01.15 (fixed in 02.01.15)
- Lite-On Technology Corporation Ff-RFI079I4: before 02.01.15 (fixed in 02.01.15)
Published 2026-09-15. Last modified 2026-09-16.