Impact
A stack-based buffer overflow exists in the sub_44B50C function of the Web Management CGI on Comfast CF‑N1‑S devices. The /cgi-bin/mbox-config?method=SET§ion=ptest_channel endpoint accepts input that overflows a local buffer, enabling an attacker to corrupt the call stack and execute arbitrary code. This vulnerability can be triggered remotely from any network connected to the device, and a public exploit demonstrating the control‑flow hijack has been released.
Affected Systems
The flaw affects Comfast CF‑N1‑S routers running firmware version 2.6.0.1. No other firmware revisions are stated to be vulnerable in the advisory.
Risk and Exploitability
The CVSS base score of 9.4 reflects a severe risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, but the presence of a remote attack vector and a publicly available exploit make it highly likely to be targeted. Likely attack will involve sending crafted data to the exposed web endpoint from an external network to trigger the overflow and gain code execution.
OpenCVE Enrichment