<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Baicells - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/baicells/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 14 Aug 2026 04:06:03 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/baicells/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote OS Command Injection in Baicells EG3661M LuCI Interface</title><link>https://feed.craftedsignal.io/briefs/2026-08-baicells-rce/</link><pubDate>Fri, 14 Aug 2026 04:06:03 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-baicells-rce/</guid><description>The Baicells EG3661M router running firmware BaiCE_BQ6_2.0.5.3_NA is vulnerable to unauthenticated or privileged OS command injection via the LuCI web interface.</description><content:encoded><![CDATA[<p>A remote OS command injection vulnerability (CVE-2026-19771) has been identified in the Baicells EG3661M wireless router, specifically affecting firmware version BaiCE_BQ6_2.0.5.3_NA. The flaw exists within the LuCI web interface component, specifically within the /cgi-bin/luci file. An attacker can trigger this vulnerability by manipulating specific input arguments, namely 'MaxHops', 'Timeout', or 'Size'. Successful exploitation allows for the execution of arbitrary operating system commands on the affected device. Public exploit code for this vulnerability is available, and the vendor has not provided a response or a patch as of the time of disclosure.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The attacker identifies an internet-facing Baicells EG3661M device running the vulnerable firmware.</li>
<li>The attacker navigates to the management interface hosted on the device.</li>
<li>The attacker prepares a crafted HTTP request targeting the /cgi-bin/luci endpoint.</li>
<li>The attacker injects malicious shell metacharacters into one of the vulnerable parameters: MaxHops, Timeout, or Size.</li>
<li>The web server process, executing with elevated privileges, improperly sanitizes the input before passing it to a system call.</li>
<li>The injected OS command is executed by the router's underlying operating system.</li>
<li>The attacker achieves persistent remote command execution to perform further malicious actions, such as configuration modification or credential theft.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full control over the affected Baicells EG3661M device. Given that these are routing and networking appliances, impact includes potential interception of network traffic, device bricking, or utilization of the router as a pivot point within the local network.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the isolation of the management interface of all Baicells EG3661M devices from the public internet. Ensure the management interface is only accessible via a secure, private network or VPN. Since the vendor has not provided a patch, consider upgrading to an alternative hardware solution or strictly enforcing access control lists (ACLs) to restrict access to the /cgi-bin/luci endpoint.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>