Impact
A flaw in COMFAST CF‑N1‑S 2.6.0.1 allows an attacker to inject operating‑system commands through the ssid field in the /cgi-bin/mbox-config CGI interface. This results in remote code execution, letting a malicious actor run arbitrary shell commands on the device and potentially compromise the entire network. The vulnerability is mapped to CWE‑77 (Command Injection) and CWE‑78 (OS Command Injection).
Affected Systems
The vulnerability affects COMFAST CF‑N1‑S routers running firmware version 2.6.0.1. No other versions were reported as affected in the current data.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. The EPSS score is 2%, indicating a low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, remote exploitation is possible via standard HTTP requests to the vulnerable CGI endpoint, and an exploit has been published and is believed to be in use.
OpenCVE Enrichment