Impact
The vulnerability is a stack‑based buffer overflow triggered by an overly long ssid value passed to the sub_44B438 function in the SSID configuration CGI. This flaw allows an attacker to overflow the stack and potentially execute arbitrary code with the privileges of the web service, leading to full compromise of the device. The flaw is listed as CWE‑119 and CWE‑121 and the CVE description states that remote exploitation is possible and public exploits exist.
Affected Systems
Vendors: Comfast. Product: CF‑N1‑S wireless router running firmware version 2.6.0.1. The affected component is the /cgi‑bin/mbox‑config web interface handling SSID settings.
Risk and Exploitability
The CVSS score of 9.4 indicates the vulnerability is critical. The EPSS score is not available but the availability of a public exploit and the remote attack vector raise the likelihood of exploitation. The flaw is not yet listed in the CISA KEV catalog; however, it should be treated as a high‑risk vulnerability that can be leveraged for arbitrary code execution on the device by any external party able to connect to its web interface.
OpenCVE Enrichment