Executive brief
A vulnerability exists in the Comfast CF-WR631AX V3 wireless router, a device used to provide high-speed Wi-Fi connectivity. An attacker can remotely take full control of the router by sending a specially crafted file upload request. This could lead to the theft of sensitive data, interception of network traffic, or a complete shutdown of the internet service.
Technical details
An OS command injection vulnerability exists in the Comfast CF-WR631AX V3 router (firmware versions up to 2.7.0.8). The flaw is located within the 'system_wl_upload_pic_file' function of the '/usr/bin/webmgnt' binary, which serves as the FastCGI Backend. By manipulating the 'filename' argument during a WiFi portal image upload, a remote attacker can execute arbitrary system commands without authentication. This occurs due to improper neutralization of special elements used in an OS command (CWE-78). As of the advisory date, the vendor has not responded to disclosure attempts, and no patch is currently available.
Affected products
- Comfast CF-WR631AX V3 2.7.0.0 to 2.7.0.8
Timeline
- 2026-07-12: disclosed: Public disclosure of the vulnerability and exploit details.
- 2026-07-12: advisory