Junglewise Threat Intelligence

CVE-2026-94003: Comfast CF-N1-S stack-based buffer overflow in web management

CVE-2026-94003 · Severity: critical · CVSS 10 · Published 2026-09-20

Technologies: Comfast CF-N1-S. Vendors: Comfast.

Executive brief

Comfast's CF-N1-S router contains a stack-based buffer overflow vulnerability in its web management interface that can be exploited remotely without authentication. An attacker can send a specially crafted HTTP request to crash the management service, causing denial of service, or potentially execute arbitrary code on the device.

Technical details

The get_css_path_from_uri function in /cgi-bin/mbox-config fails to validate input length when copying URI path data into a fixed-size stack buffer, allowing a remote attacker to overflow the buffer without credentials. The vulnerable endpoint does not enforce login session validation, and the function uses only a "?" character or string terminator as a stop condition, enabling stack memory corruption including local variables, saved registers, and return addresses.

Affected products

  • Comfast CF-N1-S 2.6.0.1

Timeline

  • 2026-08-24: disclosed
  • 2026-09-20: advisory

References

Related threats