CVE-2026-2537
PoC nicheCommand Injection in Comfast CF-E4 Firmware NTP Timezone Handler
Comfast CF-E4 firmware 2.6.0.1 contains a command injection flaw (CWE-74/CWE-77) in the HTTP POST request handler of the /cgi-bin/mbox-config endpoint (method=SET, section=ntp_timezone). An attacker who can reach this endpoint sends a crafted value in the 'timestr' parameter, which is passed unsanitized into a shell command when the device's NTP timezone setting is saved, allowing arbitrary commands to run on the device. A public proof-of-concept demonstrating remote code execution exists, though the CVSS 4.0 base score of 2 (low) indicates the attack requires elevated privileges, likely an authenticated administrator session, and has limited scoped impact. Only deployments running CF-E4 firmware 2.6.0.1 (other versions unconfirmed, as the vendor did not respond to the disclosure) are known to be affected, and the attack is launched remotely over the network. Exploitation has not been confirmed in the wild, but the public exploit plus a 24.5% EPSS score (98th percentile) means opportunistic attacks are plausible in the next 30 days; the issue is not yet in CISA's KEV catalog.
What to do: No vendor patch is currently available since Comfast did not respond to the disclosure, so check firmware version 2.6.0.1 on CF-E4 devices and apply fixed firmware when the vendor publishes it. Until then, do not expose the device's web management interface to the internet (restrict to a trusted management VLAN or firewall rules), ensure administrator credentials are strong, and monitor for unexpected processes or configuration changes. As a temporary mitigation, consider blocking untrusted access to the /cgi-bin/mbox-config endpoint.
| Comfast CF-E4 firmware | 2.6.0.1 (other versions unconfirmed; vendor has not responded to the disclosure) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability was identified in Comfast CF-E4 2.6.0.1. This impacts an unknown function of the file /cgi-bin/mbox-config?method=SET§ion=ntp_timezone of the component HTTP POST Request Handler. Such manipulation of the argument timestr leads to command injection. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
- Vendors
- comfast
- Products
- cf-e4 firmware
- Weakness
- CWE-74, CWE-77
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.