Description
A vulnerability was found in Comfast CF-N1 V2 2.6.0.2. The impacted element is the function sub_44AB9C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel. The manipulation of the argument channel results in command injection. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-02-16
Score: 5.3 Medium
EPSS: 13.5% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A command‑injection vulnerability exists in the sub_44AB9C routine of the /cgi-bin/mbox-config CGI on Comfast CF‑N1 V2 firmware 2.6.0.2. Manipulating the channel argument allows an attacker to inject and execute arbitrary operating‑system commands on the router. This flaw results from improper input handling (CWE‑74) and untrusted command construction (CWE‑77). The CVE notes that the attack can be launched remotely and that the exploit has been made public.

Affected Systems

Comfast CF-N1 V2 routers with firmware version 2.6.0.2. No other vendors or product families are listed as affected, and earlier firmware releases are not mentioned.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate severity. An EPSS score of 14 % suggests a low to moderate current exploitation probability. The vulnerability is publicly disclosed and can be triggered remotely via the /cgi-bin/mbox-config endpoint; authentication requirements are not explicitly stated, implying that an unauthenticated attacker may exploit the flaw if the management interface is exposed. The vulnerability is not yet listed in the CISA KEV catalog.

Generated by OpenCVE AI on July 21, 2026 at 19:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update from Comfast to fix the command‑injection flaw (CWE‑77) and input‑validation issue (CWE‑74).
  • If an update is not immediately available, block external access to the /cgi-bin/mbox-config interface by configuring firewall rules or disabling remote management to prevent unauthenticated exploitation.
  • Place the router behind a perimeter firewall and restrict management traffic to trusted internal networks or dedicated VLANs; monitor logs for anomalous activity that may indicate attempted injection attacks.

Generated by OpenCVE AI on July 21, 2026 at 19:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 19 Feb 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Comfast cf-n1 Firmware
CPEs cpe:2.3:h:comfast:cf-n1:2:*:*:*:*:*:*:*
cpe:2.3:o:comfast:cf-n1_firmware:2.6.0.2:*:*:*:*:*:*:*
Vendors & Products Comfast cf-n1 Firmware

Tue, 17 Feb 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Feb 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Comfast
Comfast cf-n1
Vendors & Products Comfast
Comfast cf-n1

Mon, 16 Feb 2026 05:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Comfast CF-N1 V2 2.6.0.2. The impacted element is the function sub_44AB9C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel. The manipulation of the argument channel results in command injection. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Comfast CF-N1 V2 mbox-config sub_44AB9C command injection
Weaknesses CWE-74
CWE-77
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Comfast Cf-n1 Cf-n1 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T10:05:37.645Z

Reserved: 2026-02-15T09:15:24.085Z

Link: CVE-2026-2535

cve-icon Vulnrichment

Updated: 2026-02-17T17:07:11.909Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-16T05:16:07.777

Modified: 2026-06-17T10:31:15.863

Link: CVE-2026-2535

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T19:45:03Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')