CVE-2026-80217
8.7LITE-ON · FF-RFI079I4, FF-RFI078I4
A hidden functionality flaw in LITE-ON FF-RFI079I4 and FF-RFI078I4 devices allows authenticated users with enable mode access to execute arbitrary OS commands.
Executive summary
A high-severity hidden functionality vulnerability in LITE-ON network devices enables authenticated attackers to execute arbitrary OS commands, posing a significant risk to system integrity.
Vulnerability
The vulnerability is classified as a hidden functionality issue (CWE-912). It permits an authenticated user who has successfully logged into the device via SSH and obtained enable mode privileges to bypass intended restrictions and execute arbitrary operating system commands.
Business impact
Successful exploitation of this vulnerability allows an authenticated attacker to gain full command execution on the affected network hardware. Given the CVSS score of 8.7, this represents a severe risk to infrastructure, as it could lead to full device compromise, unauthorized network traffic manipulation, or the installation of persistent backdoors.
Remediation
Immediate Action: Update the firmware for the FF-RFI079I4 and FF-RFI078I4 devices to version 02.01.15 or later immediately.
Proactive Monitoring: Audit all SSH access logs for unusual enable mode activity and monitor for unexpected process execution originating from the device management interface.
Compensating Controls: Restrict SSH access to the management interface to known, trusted administrative IP addresses only, and enforce strict multi-factor authentication for all administrative sessions.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The vulnerability presents a high risk due to the potential for complete device takeover by an authenticated user. IT administrators must prioritize the application of the 02.01.15 firmware update across all affected LITE-ON devices to neutralize the hidden command execution vector.
More LITE-ON CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section