Impact
A flaw in the web management interface of Comfast CF‑WR630AX firmware allows a remote attacker to supply crafted values for the parameters timestr and display_n. These values are used in /usr/bin/webmgnt and /cgi-bin/mbox-config in a manner that leads to arbitrary code execution on the device, giving the attacker full control over the system and the ability to install, modify, or delete data.
Affected Systems
The vulnerability exists in Comfast CF‑WR630AX devices running firmware version 2.7.0.2. No other versions are noted in the advisory.
Risk and Exploitability
The lack of a publicly available CVSS score or EPSS data means the numerical severity is unknown, but remote code execution is inherently high risk. The attack can be performed over the network by sending HTTP requests with the vulnerable parameters to the exposed web interfaces, making it a network‑based exploit that can be triggered without local access.
OpenCVE Enrichment