Impact
The vulnerability resides.2. Malicious manipulation of the bandwidth parameter allows an attacker to inject arbitrary shell commands, giving them the ability to execute code on the device. This is a classic example of command injection, classified under CWE‑74 and CWE‑77. The impact is the compromise of confidentiality, integrity, and availability of the device.
Affected Systems
Affected systems are Comfast CF‑N1 V2 routers running firmware version 2.6.0.2. The vendor is Comfast; the product name is CF‑N1 V2. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score is 5.3. The EPSS score of 0.13049% indicates a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is inferred to be remote, as the exploit can be initiated over the network without prior local access.
OpenCVE Enrichment