Description
A security vulnerability has been detected in COMFAST CF-N1-S 2.6.0.1. Impacted is the function sub_44A968 of the file /cgi-bin/mbox-config?method=SET&section=ptest_macaddress. Such manipulation of the argument macaddress leads to command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-08-17
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a command injection flaw in the sub_44A968 function of the /cgi-bin/mbox-config endpoint, allowing an attacker to supply a crafted macaddress value that results in arbitrary command execution on the device. Because the affected argument is reachable over the web interface, the flaw can be exploited from a remote host, leading to full compromise of the affected COMFAST CF‑N1‑S unit. The exploit has already been publicly disclosed and can be used by attackers who gain network access to the device.

Affected Systems

COMFAST CF‑N1‑S devices running firmware version 2.6.0.1 are vulnerable. No other COMFAST products or firmware revisions are known to be affected.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity, and the EPSS score is not available, suggesting a limited but non‑zero likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. The vulnerability is remotely exploitable via the web interface and requires only the ability to send HTTP requests with a manipulated macaddress parameter. Because the vendor did not respond to the disclosure, the risk remains high for exposed devices.

Generated by OpenCVE AI on August 17, 2026 at 04:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a newer firmware release that removes the vulnerable sub_44A968 function or fixes the command injection issue.
  • Restrict access to the /cgi-bin/mbox-config endpoint to trusted internal hosts or use a VPN to limit exposure to the web interface.
  • Disable the ptest_macaddress configuration section entirely, if possible, or block requests containing the macaddress parameter using a firewall or ACL.

Generated by OpenCVE AI on August 17, 2026 at 04:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in COMFAST CF-N1-S 2.6.0.1. Impacted is the function sub_44A968 of the file /cgi-bin/mbox-config?method=SET&section=ptest_macaddress. Such manipulation of the argument macaddress leads to command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title COMFAST CF-N1-S mbox-config sub_44A968 command injection
First Time appeared Comfast
Comfast cf-n1-s
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:comfast:cf-n1-s:*:*:*:*:*:*:*:*
Vendors & Products Comfast
Comfast cf-n1-s
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.6, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-17T02:45:11.135Z

Reserved: 2026-08-16T11:59:46.359Z

Link: CVE-2026-19976

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T03:16:50.333

Modified: 2026-08-17T03:16:50.333

Link: CVE-2026-19976

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T04:30:03Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')