Impact
The vulnerability allows an attacker to inject arbitrary operating system commands through the filename parameter of the system_wl_upload_pic_file function in the FastCGI Backend web management component. This improper handling of user input can lead to remote code execution, providing the attacker with complete control over the affected device. The weakness is a classic command injection scenario, classified under CWE‑77 and CWE‑78.
Affected Systems
Devices running the Comfast CF‑WR631AX V3 firmware up to version 2.7.0.8 are affected. The flaw exists specifically in the webmgnt interface located at */usr/bin/webmgnt* and involves the image upload functionality exposed by the system_wl_upload_pic_file endpoint.
Risk and Exploitability
The CVSS score of 9.3 marks this flaw as a critical risk. The EPSS score of 3% indicates a non‑negligible exploitation probability, and the vulnerability has already been publicly disclosed and is likely to have active exploitation. The lack of a KEV listing does not reduce the severity, as the exploit path remains straightforward: a remote attacker can trigger the upload endpoint and supply a specially crafted filename to execute arbitrary commands on the device.
OpenCVE Enrichment