Junglewise Threat Intelligence

CVE-2026-15511: Comfast CF-WR631AX V3 command injection in FastCGI Backend

CVE-2026-15511 · Severity: critical · CVSS 9.8 · Published 2026-07-12

Vendors: Comfast.

Executive brief

A vulnerability exists in the Comfast CF-WR631AX V3 wireless router, a device used to provide high-speed Wi-Fi connectivity. An attacker can remotely take full control of the router by sending a specially crafted file upload request. This could lead to the theft of sensitive data, interception of network traffic, or a complete shutdown of the internet service.

Technical details

An OS command injection vulnerability exists in the Comfast CF-WR631AX V3 router (firmware versions up to 2.7.0.8). The flaw is located within the 'system_wl_upload_pic_file' function of the '/usr/bin/webmgnt' binary, which serves as the FastCGI Backend. By manipulating the 'filename' argument during a WiFi portal image upload, a remote attacker can execute arbitrary system commands without authentication. This occurs due to improper neutralization of special elements used in an OS command (CWE-78). As of the advisory date, the vendor has not responded to disclosure attempts, and no patch is currently available.

Affected products

  • Comfast CF-WR631AX V3 2.7.0.0 to 2.7.0.8

Timeline

  • 2026-07-12: disclosed: Public disclosure of the vulnerability and exploit details.
  • 2026-07-12: advisory

References

Related threats