Impact
The vulnerability resides in the sub_41ACCC function within the webmggnt component of Comfast CF‑E7. By manipulating the timestr argument to /cgi-bin/mbox-config?method=SET§ion=ntp_timezone, an attacker can inject arbitrary shell commands. The resulting command injection allows remote execution of code with the privileges of the webmggnt process, effectively compromising the router.
Affected Systems
Affected devices are Comfast CF‑E7 routers running firmware version 2.6.0.9. No other firmware versions are specifically listed as vulnerable, but any device with the same webmggnt component unpatched may also be at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, and the EPSS score is below 1%, suggesting a low likelihood of exploitation at present. The vulnerability is not listed in the KEV catalog, but public exploits are available and may be used. An attacker can trigger it remotely over the Internet by sending a crafted HTTP request. If exploited, the router could be controlled, leading to network compromise or further attacks.
OpenCVE Enrichment