Junglewise Threat Intelligence

CVE-2026-80217: Lite-On O-RU hidden functionality arbitrary command execution via SSH

CVE-2026-80217 · Severity: high · CVSS 8.8 · Published 2026-09-15

Executive brief

Lite-On O-RU (Open Radio Unit) devices FF-RFI079I4 and FF-RFI078I4 contain hidden functionality that allows authenticated SSH users with enable mode access to execute arbitrary operating system commands. This vulnerability could allow an attacker with valid SSH credentials to compromise the radio unit, potentially disrupting 5G network operations or accessing sensitive network infrastructure data.

Technical details

The vulnerability is classified as hidden functionality (CWE-912) in Lite-On O-RU firmware versions prior to v02.01.15. An attacker who has SSH authentication credentials and can access enable mode on the affected device can execute arbitrary OS commands, leading to full system compromise. The attack requires network access to the device's SSH port and valid authentication credentials but does not require any user interaction. The vulnerability has been assigned CVE-2026-80217 with a CVSS 3.0 score of 8.8. Patches are available by updating firmware to v02.01.15 or later.

Affected products

  • Lite-On O-RU FF-RFI079I4 prior to v02.01.15
  • Lite-On O-RU FF-RFI078I4 prior to v02.01.15

Timeline

  • 2026-09-15: disclosed

References