Impact
A command injection flaw was discovered in the Comfast CF‑N1 V2 router firmware 2.6.0.2. The vulnerability resides in the sub_44AB9C routine of the /cgi‑bin/mbox‑config CGI handler. By supplying a specially crafted value for the channel parameter, an attacker can execute arbitrary operating‑system commands on the router, which can lead to full remote compromise, allowing data exfiltration or pivoting to other internal assets. The flaw is reportable as a remote attack that requires only an ability to reach the router’s management interface over HTTP or HTTPS.
Affected Systems
The impact is limited to Comfast CF‑N1 V2 routers running firmware version 2.6.0.2. Earlier firmware releases are not mentioned as affected, and no other manufacturers or products are known to be impacted. Management interfaces that expose the /cgi‑bin/mbox‑config endpoint remain the only affected component.
Risk and Exploitability
The CVSS base score is 5.3, indicating a moderate severity. The EPSS score is less than 1 %, suggesting low current exploitation probability, yet the vulnerability is publicly available and the attack can be performed remotely, meaning that an attacker who discovers the router could immediately exploit it. The vulnerability is not listed in the CISA KEV catalog, so it has not yet been confirmed as exploited in the wild. Attackers can gain shell access without authentication, so the risk persists until a firmware update or a mitigation is applied.
OpenCVE Enrichment