Impact
The vulnerability exists in the update_interface_png handler of Comfast firmware, where a display_name input is unsanitized before being concatenated into an unquoted shell command. The command runs under root privileges via system(), permitting a remote authenticated attacker to inject arbitrary shell commands and execute them with full system privileges.
Affected Systems
Affected devices include Comfast CF‑N1‑S firmware version 2.6.0.1 and CF‑WR630AX dated 2024‑01‑30. No other vendors or products are listed as affected.
Risk and Exploitability
No CVSS or EPSS score is publicly available, and the vulnerability is not listed in the CISA KEV catalog. However, the flaw allows direct command execution from an authenticated session on the web‑management interface, making it highly dangerous for any device that receives such traffic. Attackers would need legitimate credentials to the router’s web interface, after which the injection could execute arbitrary commands as root.
OpenCVE Enrichment