← Terug naar overzicht

A command injection vulnerability has been discovered in Comfast CF-N1-S firmware version 2.6.0.1. The flaw resides in the system function accessible via the CGI endpoint /cgi-bin/mbox-config?method=SET&section=ntp_timezone. Attackers can exploit this by manipulating the 'timestr' argument to inject arbitrary OS commands. The vulnerability is remotely exploitable without requiring physical access to the device. A public exploit has already been released, significantly increasing the risk of active exploitation. The affected product is a network device (likely a wireless access point or router), making this a network infrastructure concern. The CVE has been tracked and documented on NVD, VulDB, and GitHub. Given the public exploit availability and remote exploitability, this vulnerability poses a high risk to organizations using the affected hardware. Users are advised to apply patches or mitigations as soon as they become available.

Affected products

  • Comfast CF-N1-S 2.6.0.1

Related CVE's

  • CVE-2026-77683

Categories

  • Mobile & IoT
  • Network Infrastructure