A command injection vulnerability has been discovered in Comfast CF-N1-S firmware version 2.6.0.1. The flaw resides in the system function accessible via the CGI endpoint /cgi-bin/mbox-config?method=SET§ion=ntp_timezone. Attackers can exploit this by manipulating the 'timestr' argument to inject arbitrary OS commands. The vulnerability is remotely exploitable without requiring physical access to the device. A public exploit has already been released, significantly increasing the risk of active exploitation. The affected product is a network device (likely a wireless access point or router), making this a network infrastructure concern. The CVE has been tracked and documented on NVD, VulDB, and GitHub. Given the public exploit availability and remote exploitability, this vulnerability poses a high risk to organizations using the affected hardware. Users are advised to apply patches or mitigations as soon as they become available.