Junglewise Threat Intelligence

CVE-2026-77853: Lite-On O-RU OS command injection in M-Plane

CVE-2026-77853 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Lite-On O-RU devices (radio units used in 5G networks) contain an OS command injection vulnerability in their management interface. An authenticated user with access to the M-Plane (NETCONF) can execute arbitrary operating system commands, potentially compromising the entire radio unit and the network it serves.

Technical details

The vulnerability is an OS command injection (CWE-78) in the M-Plane (NETCONF) management interface of Lite-On O-RU devices. An authenticated user with M-Plane access can inject specially crafted commands that are improperly neutralized, allowing execution of arbitrary OS commands with elevated privileges. No user interaction is required beyond authentication. Exploitation provides complete compromise of the radio unit (confidentiality, integrity, and availability impact). The vendor has released firmware version v02.01.15 or later to remediate this issue.

Affected products

  • Lite-On FF-RFI079I4 prior to v02.01.15
  • Lite-On FF-RFI078I4 prior to v02.01.15

Timeline

  • 2026-09-15: disclosed

References