CVE-2026-15511 is a high-severity vulnerability in Comfast CF-WR631AX V3, allowing remote attackers to inject OS commands via the system_wl_upload_pic_file function. The vulnerability has a CVSS score of 8.9 and is classified as HIGH. The affected component is the FastCGI Backend, specifically the /usr/bin/webmgnt file. The exploit has been publicly disclosed, and the vendor has not responded to the discl [truncated]
CVE-2026-12814 is a low-severity command injection vulnerability in Comfast CF-WR631AX V3 routers up to version 2.7.0.8. The vulnerability affects the /cgi-bin/mbox-config?section=ping_config API endpoint, allowing remote attackers to inject OS commands via the 'destination' argument. The CVSS score is 2.1, indicating a low severity. The exploit has been published, but the vendor did not respond to the di [truncated]