Junglewise Threat Intelligence

CVE-2026-19976: COMFAST CF-N1-S command injection in mbox-config

CVE-2026-19976 · Severity: medium · CVSS 6.6 · Published 2026-08-17

Technologies: Comfast CF-N1-S. Vendors: Comfast.

Executive brief

COMFAST CF-N1-S is a network device used in IoT and home networking applications. A command injection vulnerability in the web configuration interface allows remote attackers to execute arbitrary commands on the device without authentication, potentially compromising the device and any network it protects.

Technical details

A command injection vulnerability exists in the /cgi-bin/mbox-config CGI script of COMFAST CF-N1-S firmware version 2.6.0.1, specifically in the function sub_44A968. The vulnerability occurs when unsanitized user input in the macaddress parameter is passed to the ptest_macaddress section. An attacker can inject arbitrary shell commands via the macaddress argument, which are executed with device privileges. The vulnerability is network-accessible and does not require prior authentication. Exploitation allows complete remote code execution on the affected device. The vendor has not released patches despite early notification.

Affected products

  • COMFAST CF-N1-S 2.6.0.1

Timeline

  • 2026-08-17: disclosed
  • 2026-08-17: kev added: CVE-2026-19976

References

Related threats