Impact
A command injection flaw exists in the sub_41ACCC function of the webmggnt component of Comfast CF‑E7 routers. The vulnerability is triggered by manipulating the timestr argument of the /cgi-bin/mbox-config?method=SET§ion=ntp_timezone endpoint. An attacker can supply crafted input that is passed directly to the underlying shell, allowing arbitrary command execution with the router’s management interface.
Affected Systems
Affected devices are Comfast CF‑E7 routers running firmware 2.6.0.9. The CVE references this specific revision; the vulnerability may exist in other firmware versions, but this is not confirmed.
Risk and Exploitability
The CVSS base score of 5.3 indicates medium severity. The EPSS score of 17% suggests a relatively high likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, but public exploits are available. Attackers can trigger the injection remotely by sending a crafted HTTP request to the router’s externally accessible web interface, targeting the /cgi-bin/mbox-config endpoint.
OpenCVE Enrichment