Description
A flaw has been found in Comfast CF-E7 2.6.0.9. This affects the function sub_441CF4 of the file /cgi-bin/mbox-config?method=SET&section=ping_config of the component webmggnt. Executing a manipulation of the argument destination can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-02-20
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

A flaw in the webmggnt component of Comfast CF‑E7 routers allows an attacker to inject arbitrary operating‑system commands by manipulating the destination argument in the /cgi-bin/mbox-config?method=SET&section=ping_config API. The vulnerable code executes the supplied value directly in a system call, giving the attacker full control over the device. Successful exploitation could lead to data theft, configuration tampering, or complete device takeover.

Affected Systems

The affected product family is Comfast CF‑E7 routers running firmware version 2.6.0.9. The webmggnt web interface exposes the vulnerable CGI script, and no earlier firmware versions were noted to be safe.

Risk and Exploitability

The CVSS base score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low current probability of exploitation, even though a working exploit has been published. Attack is performed remotely through the router’s management interface and requires no local privilege. An attacker who successfully injects commands could gain full administrative control of the device, making this a critical vulnerability for exposed routers.

Generated by OpenCVE AI on April 17, 2026 at 17:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the router to a firmware release that removes the vulnerability, if available.
  • If no patch exists, limit external access to the router’s management interface by implementing firewall rules or placing the device on a separate VLAN that is not reachable from the Internet or untrusted internal segments.
  • Disable or restrict the /cgi-bin/mbox-config API endpoint if possible, or otherwise block POST requests to /cgi-bin/mbox-config with a destination parameter from untrusted sources.
  • Monitor the router’s logs for repeated or anomalous POST attempts to the webmggnt interface and investigate any suspicious activity promptly.

Generated by OpenCVE AI on April 17, 2026 at 17:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 23 Feb 2026 10:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:comfast:cf-e7_firmware:*:*:*:*:*:*:*:*

Fri, 20 Feb 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Comfast cf-e7 Firmware
CPEs cpe:2.3:h:comfast:cf-e7:-:*:*:*:*:*:*:*
cpe:2.3:o:comfast:cf-e7_firmware:2.6.0.9:*:*:*:*:*:*:*
Vendors & Products Comfast cf-e7 Firmware

Fri, 20 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 20 Feb 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Comfast
Comfast cf-e7
Vendors & Products Comfast
Comfast cf-e7

Fri, 20 Feb 2026 05:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Comfast CF-E7 2.6.0.9. This affects the function sub_441CF4 of the file /cgi-bin/mbox-config?method=SET&section=ping_config of the component webmggnt. Executing a manipulation of the argument destination can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Comfast CF-E7 webmggnt mbox-config sub_441CF4 command injection
Weaknesses CWE-74
CWE-77
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Comfast Cf-e7 Cf-e7 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T10:31:02.530Z

Reserved: 2026-02-19T17:22:22.366Z

Link: CVE-2026-2824

cve-icon Vulnrichment

Updated: 2026-02-20T14:44:14.677Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-20T06:17:01.387

Modified: 2026-04-29T01:00:01.613

Link: CVE-2026-2824

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T17:30:23Z

Weaknesses