{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/baicells/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-19771"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["EG3661M"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Baicells"],"content_html":"\u003cp\u003eA remote OS command injection vulnerability (CVE-2026-19771) has been identified in the Baicells EG3661M wireless router, specifically affecting firmware version BaiCE_BQ6_2.0.5.3_NA. The flaw exists within the LuCI web interface component, specifically within the /cgi-bin/luci file. An attacker can trigger this vulnerability by manipulating specific input arguments, namely 'MaxHops', 'Timeout', or 'Size'. Successful exploitation allows for the execution of arbitrary operating system commands on the affected device. Public exploit code for this vulnerability is available, and the vendor has not provided a response or a patch as of the time of disclosure.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies an internet-facing Baicells EG3661M device running the vulnerable firmware.\u003c/li\u003e\n\u003cli\u003eThe attacker navigates to the management interface hosted on the device.\u003c/li\u003e\n\u003cli\u003eThe attacker prepares a crafted HTTP request targeting the /cgi-bin/luci endpoint.\u003c/li\u003e\n\u003cli\u003eThe attacker injects malicious shell metacharacters into one of the vulnerable parameters: MaxHops, Timeout, or Size.\u003c/li\u003e\n\u003cli\u003eThe web server process, executing with elevated privileges, improperly sanitizes the input before passing it to a system call.\u003c/li\u003e\n\u003cli\u003eThe injected OS command is executed by the router's underlying operating system.\u003c/li\u003e\n\u003cli\u003eThe attacker achieves persistent remote command execution to perform further malicious actions, such as configuration modification or credential theft.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full control over the affected Baicells EG3661M device. Given that these are routing and networking appliances, impact includes potential interception of network traffic, device bricking, or utilization of the router as a pivot point within the local network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the isolation of the management interface of all Baicells EG3661M devices from the public internet. Ensure the management interface is only accessible via a secure, private network or VPN. Since the vendor has not provided a patch, consider upgrading to an alternative hardware solution or strictly enforcing access control lists (ACLs) to restrict access to the /cgi-bin/luci endpoint.\u003c/p\u003e\n","date_modified":"2026-08-14T04:06:03Z","date_published":"2026-08-14T04:06:03Z","id":"https://feed.craftedsignal.io/briefs/2026-08-baicells-rce/","summary":"The Baicells EG3661M router running firmware BaiCE_BQ6_2.0.5.3_NA is vulnerable to unauthenticated or privileged OS command injection via the LuCI web interface.","title":"Remote OS Command Injection in Baicells EG3661M LuCI Interface","url":"https://feed.craftedsignal.io/briefs/2026-08-baicells-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Baicells","version":"https://jsonfeed.org/version/1.1"}