Impact
The flaw allows an attacker to inject arbitrary shell commands via the timestr argument to the /cgi-bin/mbox-config?method=SET§ion=ntp_timezone endpoint. This leads to remote command execution, giving the attacker full control over the device. The weakness is a classic command injection vulnerability (CWE-77) arising from improper validation of user input (CWE-74). The publicly released exploit demonstrates the feasibility of this attack.
Affected Systems
The vulnerability affects devices running Comfast CF‑N1‑S firmware version 2.6.0.1. No other versions are listed, so only that build is known to be susceptible.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. The EPSS score is not available, but the exploit has already been released and can be launched remotely, likely over HTTP. The vulnerability is not listed in the CISA KEV catalog, yet its high severity and public exploit make it a significant risk to any network that exposes the device to the Internet or an untrusted internal network.
OpenCVE Enrichment