SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77853

HIGH · CVSS 8.8 EPSS 1.03%

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability allows authenticated users with access to the M-Plane (NETCONF) of FF-RFI079I4 and FF-RFI078I4 products to execute arbitrary OS commands due to improper handling of special characters. This could lead to unauthorized access, data manipulation, or system compromise. Organizations using these products should prioritize remediation to mitigate potential exploitation risks.

CVE
CVE-2026-77853
Severity
HIGH
CVSS
8.8
EPSS
1.03%

Original NVD Description

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.