← Browse

CVE-2026-77853

Medium

Elevated severity or exploit probability.

CVSS base
8.8 HIGH
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
1.9%
78.5th percentile
CISA KEV
Not listed
Weakness / dates
CWE-78
Published 2026-09-15 · modified 2026-09-16

Description

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.

References

Official: NVD · CVE.org