Impact
The vulnerability resides in the sub_44AC4C routine within the /cgi-bin/mbox-config component of CF‑N1 V2 firmware 2.6.0.2. Malicious manipulation of the bandwidth parameter allows an attacker to inject arbitrary shell commands, giving them the ability to execute code on the device. This is a classic example of command injection, classified under CWE‑74 and CWE‑77. The impact is the compromise of confidentiality, integrity, and availability of the device.
Affected Systems
Affected systems are Comfast CF‑N1 V2 routers running firmware version 2.6.0.2. The vendor is Comfast; the product name is CF‑N1 V2. No other vendors or products are listed as affected.
Risk and Exploitability
5.3, indicating moderate severity. EPSS is 14% and the vulnerability is not listed in the CISA KEV catalog, which indicates a moderate exploitation probability. The likely attack vector is remote; the description does not explicitly state authentication requirements, so it is inferred that the exploit can be launched without prior access.
OpenCVE Enrichment