CVE-2026-77853: Command Injection
Published Sep 15, 2026
·Updated
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.
Event History
Sep 15, 2026
CVE Published
via MITRE·08:49 AM
Data Sourced
via MITRE·08:49 AM
DescriptionSeverity
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must be able to log in to the product's M-Plane through NETCONF. The provided information does not indicate that unauthenticated attackers can exploit it.
2
What level of access could exploitation provide?
A successful attacker may execute arbitrary operating-system commands. The listed impact includes high confidentiality, integrity, and availability impact.
3
Which product versions are identified as affected?
The issue is reported in FF-RFI079I4 and FF-RFI078I4. No fixed versions, patches, or configuration workarounds are provided in the available data.