Impact
The vulnerability is a command injection flaw in the sub_44A968 function of the /cgi-bin/mbox-config endpoint, allowing an attacker to supply a crafted macaddress value that results in arbitrary command execution on the device. Because the affected argument is reachable over the web interface, the flaw can be exploited from a remote host, leading to full compromise of the affected COMFAST CF‑N1‑S unit. The exploit has already been publicly disclosed and can be used by attackers who gain network access to the device.
Affected Systems
COMFAST CF‑N1‑S devices running firmware version 2.6.0.1 are vulnerable. No other COMFAST products or firmware revisions are known to be affected.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity, and the EPSS score is not available, suggesting a limited but non‑zero likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. The vulnerability is remotely exploitable via the web interface and requires only the ability to send HTTP requests with a manipulated macaddress parameter. Because the vendor did not respond to the disclosure, the risk remains high for exposed devices.
OpenCVE Enrichment