← Terug naar overzicht

A stack-based buffer overflow vulnerability has been identified in Comfast CF-N1-S firmware version 2.6.0.1. The flaw exists in the function sub_44B438 within the SSID Configuration component, accessible via the CGI endpoint /cgi-bin/mbox-config?method=SET&section=ptest_ssid. An attacker can manipulate the 'ssid' argument to trigger the overflow remotely without authentication. The vulnerability is classified as remotely exploitable, increasing the risk of widespread exploitation. A public exploit has already been released, making this an active threat to devices running the affected firmware. Comfast CF-N1-S is a wireless networking device, placing this vulnerability in the IoT and network infrastructure space. Organizations or individuals using this device should apply patches or mitigations immediately. The vulnerability has been documented on NVD, VulDB, and GitHub, with multiple reference links available.

Affected products

  • Comfast CF-N1-S 2.6.0.1

Related CVE's

  • CVE-2026-77022

Categories

  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities