Impact
The vulnerability resides in the sub_44AC4C routine within the /cgi-bin/mbox-config component of Comfast CF‑N1 V2 firmware 2.6.0.2. Malicious manipulation of the bandwidth parameter allows an attacker to inject arbitrary shell commands, giving them the capability to execute code on the device. This is a classic example of command injection, classified under CWE‑74 and CWE‑77. The impact is the compromise of confidentiality, integrity, and availability of the affected device, potentially enabling full remote control and further lateral movement within a network.
Affected Systems
Affected systems are Comfast CF‑N1 V2 routers running firmware version 2.6.0.2. The vendor is Comfast; the product name is CF‑N1 V2. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS base score is 5.3, indicating moderate severity. EPSS is less than 1 % and the vulnerability is not present in the CISA KEV catalog, which suggests a low current exploitation probability. Nonetheless, the attack vector is remote and can be performed without authentication, however this is inferred since the description does not explicitly state authentication requirements, by sending a crafted HTTP request to the vulnerable /cgi-bin/mbox-config. Because the flaw directly exposes wrapper shell functionality, an attacker who succeeds can achieve remote code execution on the router.
OpenCVE Enrichment