Published:2026/09/15  Last Updated:2026/09/15

JVN#02049764
Multiple vulnerabilities in Lite-On O-RU "FF-RFI079I4" and "FF-RFI078I4"

Overview

O-RU "FF-RFI079I4" and "FF-RFI078I4" provided by LITE-ON Technology Corporation contain multiple vulnerabilities.

Products Affected

  • FF-RFI079I4 firmware versions prior to v02.01.15
  • FF-RFI078I4 firmware versions prior to v02.01.15

Description

O-RU "FF-RFI079I4" and "FF-RFI078I4" provided by LITE-ON Technology Corporation contain multiple vulnerabilities listed below.

  • OS Command Injection (CWE-78)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.7
    • CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Base Score 8.8
    • CVE-2026-77853
  • Hidden Functionality (CWE-912)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.7
    • CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Base Score 8.8
    • CVE-2026-80217

Impact

  • A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands (CVE-2026-77853).
  • A user who can log in via SSH and access the enable mode on the product may execute arbitrary OS commands (CVE-2026-80217).

Solution

Update the Firmware
Update the firmware to the latest version according to the information provided by the developer.

Vendor Status

Vendor Link
LITE-ON Technology Corporation LITEON Product Security Advisory

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Yuto Aono, Yutaro Osako, and Shunsuke Saruwatari of The University of Osaka reported these vulnerabilities to the developer and coordinated. After the coordination was completed, they reported the case to JPCERT/CC to notify users of the solution through JVN.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-77853
CVE-2026-80217
JVN iPedia JVNDB-2026-000133