Impact
A flaw in the webmggnt component of Comfast CF‑E7 2.6.0.9 routers allows attackers to manipulate the /cgi-bin/mbox-config?method=SET§ion=ping_config endpoint. The vulnerable function, sub_441CF4, accepts a destination parameter and passes its value directly into a system call, which results in command injection. Successful exploitation provides an attacker with the ability to execute arbitrary.
Affected Systems
The vulnerability affects Comfast CF‑E7 2.6.0.9. No evidence indicates that earlier firmware releases are immune; the exposed CGI script is present only in the reported version. Users should specifically check the firmware version deployed on their devices against the stated value.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, and the EPSS score of 13% suggests a relatively high probability of exploitation. Attack is performed remotely; it is inferred that the attacker exploits the web management interfacembox-config?method=SET§ion=ping_config endpoint, with no local privileges required. If successful, the attacker can execute arbitrary shell commands, effectively gaining administrative control, which poses a moderate to high risk for routers exposed to untrusted networks. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment