[Japanese]

JVNDB-2026-000133

Multiple vulnerabilities in Lite-On O-RU "FF-RFI079I4" and "FF-RFI078I4"

Overview

O-RU "FF-RFI079I4" and "FF-RFI078I4" provided by LITE-ON Technology Corporation contain multiple vulnerabilities listed below.
  • OS Command Injection (CWE-78) - CVE-2026-77853
  • Hidden Functionality (CWE-912) - CVE-2026-80217
Yuto Aono, Yutaro Osako, and Shunsuke Saruwatari of The University of Osaka reported these vulnerabilities to the developer and coordinated. After the coordination was completed, they reported the case to JPCERT/CC to notify users of the solution through JVN.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 8.8 (High) [IPA Score]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: High
  • Integrity Impact: High
  • Availability Impact: High
CVSS v4 Severity
Base Metrics: 8.7 (High) [IPA Score]
  • Access Vector (AV): Network
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): None
  • Privileges Required (PR): Low
  • User Interaction (UI): None
  • Vulnerable System Impact
  • Confidentiality Impact (VC): High
  • Integrity Impact (VI): High
  • Availability Impact (VA): High
  • Subsequent System Impact
  • Confidentiality Impact (SC): None
  • Integrity Impact (SI): None
  • Availability Impact (SA): None
The above CVSS base scores have been assigned for CVE-2026-77853


CVSS v3 Severity
Base Metrics: 8.8(High) [IPA Score]
  • Access Vector : Network
  • Attack Complexity : Low
  • Privileges Required : Low
  • User Interaction : None
  • Scope : Unchanged
  • Confidentiality Impact : High
  • Integrity Impact : High
  • Availability Impact : High
CVSS v4 Severity
Base Metrics: 8.7 (High) [IPA Score]
  • Access Vector (AV): Network
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): None
  • Privileges Required (PR): Low
  • User Interaction (UI): None
  • Vulnerable System Impact
  • Confidentiality Impact (VC): High
  • Integrity Impact (VI): High
  • Availability Impact (VA): High
  • Subsequent System Impact
  • Confidentiality Impact (SC): None
  • Integrity Impact (SI): None
  • Availability Impact (SA): None
The above CVSS base scores have been assigned for CVE-2026-80217
Affected Products


LITE-ON Technology Corporation
  • FF-RFI078I4 firmware versions prior to v02.01.15
  • FF-RFI079I4 firmware versions prior to v02.01.15

Impact

  • A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands (CVE-2026-77853).
  • A user who can log in via SSH and access the enable mode on the product may execute arbitrary OS commands (CVE-2026-80217).
Solution

[Update the Firmware]
Update the firmware to the latest version according to the information provided by the developer.
Vendor Information

LITE-ON Technology Corporation
CWE (What is CWE?)

  1. OS Command Injection(CWE-78) [IPA Evaluation]
  2. No Mapping(CWE-Other) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2026-77853
  2. CVE-2026-80217
References

  1. JVN : JVN#02049764
Revision History

  • [2026/09/15]
      Web page was published