PatchSiren

Comfast CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Comfast CVE published 2026-09-20

CVE-2026-94003

A vulnerability has been found in Comfast CF-N1-S 2.6.0.1, impacting the function get_css_path_from_uri of the file /cgi-bin/mbox-config in the Web Management Interface. This results in a stack-based buffer overflow, which can be exploited remotely. Defenders should assess exposure and potential vulnerabilities, especially in configurations with remote access enabled. The CVE record and NVD entry provide [truncated]

MEDIUM Comfast CVE published 2026-08-26

CVE-2026-75364

A remote authenticated attacker can inject arbitrary commands via the update_interface_png SET handler in /usr/bin/webmgnt due to improper sanitization of the display_name parameter. The vulnerability affects Comfast CF-N1-S firmware 2.6.0.1 and CF-WR630AX (2024-01-30 build). This command injection vulnerability allows an attacker to execute system commands with root privileges, potentially leading to una [truncated]

MEDIUM Comfast CVE published 2026-08-26

CVE-2026-75363

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-26T21:16:40.857Z and has not been modified since then. The vulnerability exists in Comfast CF-WR630AX v.2.7.0.2, specifically in the /usr/bin/webmgnt and /cgi-bin/mbox-config components, with parameters timestr and display_n. This could lead to potential remote code execution. Security teams should [truncated]

HIGH Comfast CVE published 2026-08-21

CVE-2026-77683

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T11:17:06.457Z and has not been modified since then. The command injection vulnerability in Comfast CF-N1-S 2.6.0.1 affects the /cgi-bin/mbox-config file, specifically the system function, allowing remote attacks. Evidence is limited to public sources and may not reflect the full scope of affected [truncated]

HIGH Comfast CVE published 2026-08-20

CVE-2026-77022

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1, specifically a stack-based buffer overflow vulnerability in the sub_44B438 function of the /cgi-bin/mbox-config?method=SET&section=ptest_ssid file. The vulnerability is triggered by manipulating the ssid argument, allowing remote attackers to execute arbitrary code. Organizations should be aware of this vulnerability and take steps to mitigat [truncated]

HIGH Comfast CVE published 2026-07-12

CVE-2026-15511

CVE-2026-15511 is a high-severity vulnerability in Comfast CF-WR631AX V3, allowing remote attackers to inject OS commands via the system_wl_upload_pic_file function. The vulnerability has a CVSS score of 8.9 and is classified as HIGH. The affected component is the FastCGI Backend, specifically the /usr/bin/webmgnt file. The exploit has been publicly disclosed, and the vendor has not responded to the discl [truncated]

LOW Comfast CVE published 2026-06-21

CVE-2026-12814

CVE-2026-12814 is a low-severity command injection vulnerability in Comfast CF-WR631AX V3 routers up to version 2.7.0.8. The vulnerability affects the /cgi-bin/mbox-config?section=ping_config API endpoint, allowing remote attackers to inject OS commands via the 'destination' argument. The CVSS score is 2.1, indicating a low severity. The exploit has been published, but the vendor did not respond to the di [truncated]