Junglewise Threat Intelligence

CVE-2026-19771: Baicells EG3661M OS command injection in LuCI web interface

CVE-2026-19771 · Severity: high · CVSS 7.2 · Published 2026-08-14

Executive brief

The Baicells EG3661M is a cellular network access point used in carrier deployments. The embedded web management interface (LuCI) contains multiple OS command injection vulnerabilities in diagnostic functions, allowing an authenticated administrator to execute arbitrary commands as root. An attacker with valid admin credentials can compromise the device completely, potentially disrupting network service or accessing sensitive network data.

Technical details

The vulnerability is an authenticated OS command injection (CWE-78) in the LuCI web interface's diagnosis_route and diagnosis_ping endpoints. These endpoints concatenate request parameters (MaxHops, Timeout, Size) directly into shell commands without input validation or metacharacter escaping. An authenticated admin can inject shell metacharacters (e.g., pipe "|") to terminate the intended command and execute arbitrary commands as root via BusyBox ash. The attack requires valid admin credentials (stok token and sysauth cookie) and network access to the web interface. Confirmed injection points yield command execution with root privileges; exploitation is straightforward and proof-of-concept code is publicly available. No patch from the vendor has been released despite early disclosure notification.

Affected products

  • Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA

Timeline

  • 2026-08-14: disclosed: Public disclosure via NVD and GitHub
  • 2025-02-20: other: Vulnerability discovery date

References