Vulnerabilities
26 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-3798 | A vulnerability was detected in Comfast CF-AC100 2.6.0.8. A vulnerability was detected in Comfast CF-AC100 2.6.0.8. This affects the function sub_44AC14 of the file /cgi-bin/mbox-config?method=SET§ion=ping_config of the component Request Path Handler. The manipulation results in command injection. The attack may be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 2.0 | 15% | PoC |
| — | |
| CVE-2026-2823 +1 in the same advisory: …2824 | A vulnerability was detected in Comfast CF-E7 2.6.0.9. A vulnerability was detected in Comfast CF-E7 2.6.0.9. The impacted element is the function sub_41ACCC of the file /cgi-bin/mbox-config?method=SET§ion=ntp_timezone of the component webmggnt. Performing a manipulation of the argument timestr results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 2.1 | 17% | PoC |
| — | |
| CVE-2026-2537 | Command Injection in Comfast CF-E4 Firmware NTP Timezone Handler Comfast CF-E4 firmware 2.6.0.1 contains a command injection flaw (CWE-74/CWE-77) in the HTTP POST request handler of the /cgi-bin/mbox-config endpoint (method=SET, section=ntp_timezone). An attacker who can reach this endpoint sends a crafted value in the 'timestr' parameter, which is passed unsanitized into a shell command when the device's NTP timezone setting is saved, allowing arbitrary commands to run on the device. A public proof-of-concept demonstrating remote code execution exists, though the CVSS 4.0 base score of 2 (low) indicates the attack requires elevated privileges, likely an authenticated administrator session, and has limited scoped impact. Only deployments running CF-E4 firmware 2.6.0.1 (other versions unconfirmed, as the vendor did not respond to the disclosure) are known to be affected, and the attack is launched remotely over the network. Exploitation has not been confirmed in the wild, but the public exploit plus a 24.5% EPSS score (98th percentile) means opportunistic attacks are plausible in the next 30 days; the issue is not yet in CISA's KEV catalog. Do: No vendor patch is currently available since Comfast did not respond to the disclosure, so check firmware version 2.6.0.1 on CF-E4 devices and apply fixed firmware when the vendor publishes it. Until then, do not expose the device's web management interface to the internet (restrict to a trusted management VLAN or firewall rules), ensure administrator credentials are strong, and monitor for unexpected processes or configuration changes. As a temporary mitigation, consider blocking untrusted access to the /cgi-bin/mbox-config endpoint. | 2.0 | 25% | PoC |
| nichelikely low thousands of internet-exposed units at most; no published install base | |
| CVE-2026-2535 +1 in the same advisory: …2534 | A vulnerability was found in Comfast CF-N1 V2 2.6.0.2. A vulnerability was found in Comfast CF-N1 V2 2.6.0.2. The impacted element is the function sub_44AB9C of the file /cgi-bin/mbox-config?method=SET§ion=ptest_channel. The manipulation of the argument channel results in command injection. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 2.1 | 14% | PoC |
| — | |
| CVE-2025-57293 | A command injection vulnerability in COMFAST CF-XR11 (firmware V2.7.2) exists in the multi_pppoe API, processed by the sub_423930 function in /usr/bin/webmgnt. A command injection vulnerability in COMFAST CF-XR11 (firmware V2.7.2) exists in the multi_pppoe API, processed by the sub_423930 function in /usr/bin/webmgnt. The phy_interface parameter is not sanitized, allowing attackers to inject arbitrary commands via a POST request to /cgi-bin/mbox-config?method=SET§ion=multi_pppoe. When the action parameter is set to "one_click_redial", the unsanitized phy_interface is used in a system() call, enabling execution of malicious commands. This can lead to unauthorized access to sensitive files, execution of arbitrary code, or full device compromise. NVD description · AI analysis pending | 8.8 | 2% | PoC |
| — | |
| CVE-2025-9586 | A vulnerability was identified in Comfast CF-N1 2.6.0. A vulnerability was identified in Comfast CF-N1 2.6.0. This vulnerability affects the function wireless_device_dissoc of the file /usr/bin/webmgnt. Such manipulation of the argument mac leads to command injection. The attack may be performed from a remote location. The exploit is publicly available and might be used. NVD description · AI analysis pending | 2.1 | 8% | PoC |
| — | |
| CVE-2024-44466 | COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter iface. NVD description · AI analysis pending | 9.8 | 11% | PoC |
| — | |
| CVE-2023-38866 | COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588. COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter interface and display_name. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2022-45725 +1 in the same advisory: …45724 | Improper Input Validation in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to execute arbitrary code on the target via an HTTP P Improper Input Validation in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to execute arbitrary code on the target via an HTTP POST request NVD description · AI analysis pending | 8.8 group max | 7% | PoC |
| — | |
| CVE-2022-47699 | COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 is vulnerable to Incorrect Access Control. COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 is vulnerable to Incorrect Access Control. NVD description · AI analysis pending | 9.8 group max | <1% |
| — |