Executive brief
Comfast's CF-N1-S router contains a stack-based buffer overflow vulnerability in its web management interface that can be exploited remotely without authentication. An attacker can send a specially crafted HTTP request to crash the management service, causing denial of service, or potentially execute arbitrary code on the device.
Technical details
The get_css_path_from_uri function in /cgi-bin/mbox-config fails to validate input length when copying URI path data into a fixed-size stack buffer, allowing a remote attacker to overflow the buffer without credentials. The vulnerable endpoint does not enforce login session validation, and the function uses only a "?" character or string terminator as a stop condition, enabling stack memory corruption including local variables, saved registers, and return addresses.
Affected products
- Comfast CF-N1-S 2.6.0.1
Timeline
- 2026-08-24: disclosed
- 2026-09-20: advisory