Impact
A command‑injection vulnerability exists in the function sub_44AB9C of the file /cgi-bin/mbox-config?method=SET§ion=ptest_channel on Comfast CF‑N1 V2 firmware 2.6.0.2. Manipulating the channel argument allows an attacker to inject and execute arbitrary operating‑system commands on the router. This flaw results from improper input handling (CWE‑74) and untrusted command construction (CWE‑77). The CVE notes that the attack can be launched remotely and that the exploit has been made public.
Affected Systems
Comfast CF‑N1 V2 routers with firmware version 2.6.0.2. No other vendors or product families are listed as affected, and earlier firmware releases are not mentioned.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. An EPSS score of 14 % suggests a low to moderate current exploitation probability. The vulnerability is publicly disclosed and can be triggered remotely via the /cgi-bin/mbox-config endpoint; authentication requirements are not explicitly stated. Therefore, it is possible that an unauthenticated attacker could exploit the flaw if the management interface is exposed. The vulnerability is not yet listed in the CISA KEV catalog.
OpenCVE Enrichment