CyberRota Analysis
AI-GeneratedThe vulnerability allows authenticated users with access to the M-Plane (NETCONF) of FF-RFI079I4 and FF-RFI078I4 products to execute arbitrary OS commands due to improper handling of special characters. This could lead to unauthorized access, data manipulation, or system compromise. Organizations using these products should prioritize remediation to mitigate potential exploitation risks.
CVE
CVE-2026-77853
Severity
HIGH
CVSS
8.8
EPSS
1.03%
Original NVD Description
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.