Description
A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component CGI Interface. This manipulation of the argument ssid causes os command injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Published: 2026-08-18
Score: 9.4 Critical
EPSS: 2.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in COMFAST CF‑N1‑S 2.6.0.1 allows an attacker to inject operating‑system commands through the ssid field in the /cgi-bin/mbox-config CGI interface. This results in remote code execution, letting a malicious actor run arbitrary shell commands on the device and potentially compromise the entire network. The vulnerability is mapped to CWE‑77 (Command Injection) and CWE‑78 (OS Command Injection).

Affected Systems

The vulnerability affects COMFAST CF‑N1‑S routers running firmware version 2.6.0.1. No other versions were reported as affected in the current data.

Risk and Exploitability

The CVSS score of 9.4 indicates critical severity. The EPSS score is 2%, indicating a low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, remote exploitation is possible via standard HTTP requests to the vulnerable CGI endpoint, and an exploit has been published and is believed to be in use.

Generated by OpenCVE AI on August 18, 2026 at 14:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the CF‑N1‑S firmware to a version that contains the fix once COMFAST releases it.
  • If an update is not yet available, block external access to the /cgi-bin/mbox-config endpoint by configuring firewall rules or network segmentation to prevent attackers from reaching the vulnerable interface.
  • Enable and review system logs for unusual shell command activity or repeated access attempts to mbox-config, and investigate any suspicious activity promptly.

Generated by OpenCVE AI on August 18, 2026 at 14:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Description A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component CGI Interface. This manipulation of the argument ssid causes os command injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Title COMFAST CF-N1-S CGI mbox-config sub_44B438 os command injection
First Time appeared Comfast
Comfast cf-n1-s
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:comfast:cf-n1-s:*:*:*:*:*:*:*:*
Vendors & Products Comfast
Comfast cf-n1-s
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-18T14:15:42.370Z

Reserved: 2026-08-17T16:46:50.116Z

Link: CVE-2026-75094

cve-icon Vulnrichment

Updated: 2026-08-18T14:15:36.567Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T02:17:30.757

Modified: 2026-08-20T12:48:31.843

Link: CVE-2026-75094

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T14:45:03Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')