Description
A flaw has been found in Comfast CF-WR631AX V3 up to 2.7.0.8. This issue affects the function system of the file /cgi-bin/mbox-config?section=ping_config of the component API Endpoint. This manipulation of the argument destination causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-06-21
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw allows an attacker to inject arbitrary operating‑system commands by manipulating the 'destination' parameter in the /cgi-bin/mbox-config?section=ping_config API endpoint. The injection can be executed remotely, giving the attacker full control over the device’s operating system. The weakness maps to CWE-77 and CWE-78, representing Command Injection and OS Command Injection respectively.

Affected Systems

The vulnerability is present in Comfast CF‑WR631AX V3 firmware versions up to 2.7.0.8. Only devices running affected firmware are impacted; newer firmware releases may have the fix.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. No EPSS value is currently available, and the vulnerability is not listed in the CISA KEV catalog, but published exploits exist. The attack can be carried out remotely via the API endpoint, and the description indicates that no authentication is required, though this is inferred from the wording of the advisory and not explicitly stated in the data.

Generated by OpenCVE AI on June 22, 2026 at 00:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware release from Comfast that removes the vulnerable endpoint or patches the command injection flaw.
  • Configure network perimeter devices or the router’s firewall to block access to the /cgi-bin/mbox-config endpoint from untrusted networks.
  • Perform a security review of the router’s configuration to ensure that no other API endpoints or settings expose command execution capabilities.

Generated by OpenCVE AI on June 22, 2026 at 00:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 21 Jun 2026 23:00:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Comfast CF-WR631AX V3 up to 2.7.0.8. This issue affects the function system of the file /cgi-bin/mbox-config?section=ping_config of the component API Endpoint. This manipulation of the argument destination causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Comfast CF-WR631AX V3 API Endpoint mbox-config system os command injection
First Time appeared Comfast
Comfast cf-wr631ax V3
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:comfast:cf-wr631ax_v3:*:*:*:*:*:*:*:*
Vendors & Products Comfast
Comfast cf-wr631ax V3
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Comfast Cf-wr631ax V3
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-06-21T22:45:08.850Z

Reserved: 2026-06-21T06:22:24.256Z

Link: CVE-2026-12814

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-22T02:30:17Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')