Executive brief
The Comfast CF-N1-S is a networking device used in small business and residential deployments. A vulnerability in its web configuration interface allows remote attackers to inject arbitrary commands by manipulating request parameters, potentially leading to complete device compromise and network infiltration.
Technical details
A command injection vulnerability exists in the /cgi-bin/mbox-config endpoint (method=SET§ion=ptest_sn) due to unsafe use of the sprintf function when processing the sn argument. The vulnerability is reached over the network without requiring authentication. An attacker can manipulate the sn parameter to inject shell commands that execute with device privileges. The exploit code has been publicly released.
Affected products
- Comfast CF-N1-S 2.6.0.1
Timeline
- 2026-08-20: disclosed: Advisory published on NVD