← Terug naar overzicht

A command injection vulnerability has been discovered in Comfast CF-N1-S firmware version 2.6.0.1. The flaw exists in the sprintf function within the /cgi-bin/mbox-config CGI endpoint when the method is SET and section is ptest_sn. An attacker can manipulate the 'sn' argument to inject arbitrary commands. The vulnerability is remotely exploitable without requiring physical access to the device. A public exploit has already been published and is available for use, increasing the risk of active exploitation. This affects network/IoT devices running the vulnerable firmware version. The issue has been assigned CVE-2026-77004 and documented on NVD and VulDB. Organizations using Comfast CF-N1-S devices should review exposure and apply mitigations promptly.

Affected products

  • Comfast CF-N1-S 2.6.0.1

Related CVE's

  • CVE-2026-77004

Categories

  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities