Impact
A flaw in the web management interface of Comfast CF‑WR630AX firmware allows a remote attacker to supply crafted values for the parameters timestr and display_n. These values are used in /usr/bin/webmgnt and /cgi-bin/mbox-config in a manner that leads to arbitrary code execution on the device, giving the attacker full control over the system and the ability to install, modify, or delete data.
Affected Systems
The vulnerability exists in Comfast CF‑WR630AX devices running firmware version 2.7.0.2. No other versions are noted in the advisory.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate severity vulnerability that can be exploited remotely. The EPSS score of < 1% suggests a low probability of exploitation in the wild, but the vulnerability remains listed as not in KEV. The attack can be performed over the network by sending HTTP requests with the vulnerable parameters to the exposed web interfaces, making it a network‑based exploit that can be triggered without local access.
OpenCVE Enrichment