What is CVE-2026-19771?
An OS command injection vulnerability exists in the LuCI web interface's `/cgi-bin/luci` file on Baicells EG3661M devices. Remote attackers can execute arbitrary commands via manipulation of the `MaxHops`, `Timeout`, or `Size` arguments. Immediately update the firmware and restrict access to the interface.
Azərbaycanca: Baicells EG3661M cihazının LuCI veb interfeysindəki `/cgi-bin/luci` faylında OS əmr inyeksiyası zəifliyi aşkarlanıb. `MaxHops`, `Timeout` və `Size` arqumentləri vasitəsilə uzaqdan əmr icrası mümkündür. Cihaz dərhal ən son proqram təminatı ilə yenilənməli və interfeysə giriş məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Which file on the Baicells EG3661M device is vulnerable to OS command injection?
It was discovered in the `/cgi-bin/luci` file within the LuCI web interface.
How can I protect my device from CVE-2026-19771?
You should immediately update the device to the latest firmware and restrict access to the interface.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.