Impact
A stack‑based buffer overflow exists in the get_css_path_from_uri function of the Web Management Interface on Comfast CF‑N1‑S devices. The flaw is triggered by manipulating an input parameter, and the overflow can be exploited from a remote host, potentially allowing an attacker to execute arbitrary code on the appliance.
Affected Systems
The vulnerability affects the Comfast CF‑N1‑S model running firmware 2.6.0.1. Only devices with that exact firmware revision are known to be vulnerable.
Risk and Exploitability
The CVSS score is 10, indicating a critical severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalogue, but the exploit has been publicly disclosed and can be used by an attacker who can reach the device’s management interface. If exploited, the attacker could gain full control over the device and potentially compromise the associated network.
OpenCVE Enrichment