Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 14 Aug 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component LuCI Web Interface. Such manipulation of the argument MaxHops/Timeout/Size leads to os command injection. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Baicells EG3661M LuCI Web luci os command injection | |
| First Time appeared |
Baicells
Baicells eg3661m |
|
| Weaknesses | CWE-77 CWE-78 |
|
| CPEs | cpe:2.3:a:baicells:eg3661m:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Baicells
Baicells eg3661m |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-14T01:45:08.073Z
Reserved: 2026-08-13T17:17:29.351Z
Link: CVE-2026-19771
No data.
Status : Deferred
Published: 2026-08-14T02:16:24.903
Modified: 2026-08-14T19:09:39.140
Link: CVE-2026-19771
No data.
OpenCVE Enrichment
Updated: 2026-08-14T14:45:17Z