Impact
A command‑injection vulnerability exists in the sub_44AB9C routine of the /cgi-bin/mbox-config CGI on Comfast CF‑N1 V2 firmware 2.6.0.2. Manipulating the channel argument allows an attacker to inject and execute arbitrary operating‑system commands on the router. This flaw results from improper input handling (CWE‑74) and untrusted command construction (CWE‑77). The CVE notes that the attack can be launched remotely and that the exploit has been made public.
Affected Systems
Comfast CF-N1 V2 routers with firmware version 2.6.0.2. No other vendors or product families are listed as affected, and earlier firmware releases are not mentioned.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. An EPSS score of 14 % suggests a low to moderate current exploitation probability. The vulnerability is publicly disclosed and can be triggered remotely via the /cgi-bin/mbox-config endpoint; authentication requirements are not explicitly stated, implying that an unauthenticated attacker may exploit the flaw if the management interface is exposed. The vulnerability is not yet listed in the CISA KEV catalog.
OpenCVE Enrichment