Impact
The vulnerability resides in the sprintf call within the mbox-config CGI of Comfast CF-N1-S firmware 2.6.0.1. The function improperly handles the sn argument, allowing an attacker to construct a malicious string that the underlying system executes as a shell command. Remote exploitation therefore can grant the attacker arbitrary command execution on the device, compromising confidentiality, integrity, and availability of the affected network appliance.
Affected Systems
This flaw affects Comfast CF‑N1‑S devices running firmware version 2.6.0.1. No other products or versions are listed in the official CNA data.
Risk and Exploitability
The CVSS score of 5.3 classifies the risk as moderate, yet the vulnerability is exploitable from outside the network and an exploit has already been published. With no EPSS value reported and the vulnerability not listed in the CISA KEV catalog, the likelihood of widespread exploitation is uncertain, but the remote command injection capability demands immediate attention.
OpenCVE Enrichment