← Back to overview

A stack-based buffer overflow vulnerability has been identified in Comfast CF-N1-S firmware version 2.6.0.1. The flaw resides in the function sub_41AD7C within the Web Management component, specifically via the CGI endpoint /cgi-bin/mbox-config?method=SET&section=ntp_timezone. Manipulation of the arguments timestr or ntp_client_enabled can trigger the overflow. The vulnerability is remotely exploitable without physical access to the device. A public exploit has already been released, increasing the risk of active exploitation. The affected product is a networking device, making it a potential target for network-level attacks. No patch information is currently mentioned in the article. The vulnerability has been assigned CVE-2026-78050 and is tracked on NVD, VulDB, and GitHub. Given the public exploit availability and remote exploitability, this is considered a high-severity issue.

Affected products

  • Comfast CF-N1-S 2.6.0.1

Related CVE's

  • CVE-2026-78050

Categories

  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities