← back
CVE-2026-75094criticalCWE-77CWE-78

COMFAST CF-N1-S CGI mbox-config sub_44B438 os command injection

48Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendcvss 9.4epss 2.1%
exploitation probability
2.1%top 20% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component CGI Interface. This manipulation of the argument ssid causes os command injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P
Affected products
COMFAST · CF-N1-S
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.