Impact
A flaw in the webmggnt component of Comfast CF‑E7 routers allows an attacker to inject arbitrary operating‑system commands by manipulating the destination argument in the /cgi-bin/mbox-config?method=SET§ion=ping_config API. The vulnerable code executes the supplied value directly in a system call, giving the attacker full control over the device. Successful exploitation could lead to data theft, configuration tampering, or complete device takeover.
Affected Systems
The affected product family is Comfast CF‑E7 routers running firmware version 2.6.0.9. The webmggnt web interface exposes the vulnerable CGI script, and no earlier firmware versions were noted to be safe.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low current probability of exploitation, even though a working exploit has been published. Attack is performed remotely through the router’s management interface and requires no local privilege. An attacker who successfully injects commands could gain full administrative control of the device, making this a critical vulnerability for exposed routers.
OpenCVE Enrichment