Cf N1 S Comfast Cf N1 S

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Comfast Cf N1 S.

By the Year

In 2026 there have been 7 vulnerabilities in Comfast Cf N1 S with an average score of 8.3 out of ten.

Year Vulnerabilities Average Score
2026 7 8.29

It may take a day or so for new Cf N1 S vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Comfast Cf N1 S Security Vulnerabilities

Command Injection in Comfast CF-N1-S 2.6.0.1 via /cgi-bin/mbox-config
CVE-2026-77683 9.4 - Critical - August 21, 2026

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone. The manipulation of the argument timestr results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

Command Injection

Comfast CF-N1-S 2.6.0.1 WebMgmt Stack Buffer Overflow Vulnerability
CVE-2026-77148 9.4 - Critical - August 20, 2026

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel of the component Web Management. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.

Stack Overflow

Comfast CFN1S 2.6.0.1 SSID Config Stack Buffer Overflow
CVE-2026-77022 9.4 - Critical - August 20, 2026

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component SSID Configuration. The manipulation of the argument ssid results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

Stack Overflow

Command Injection in CFN1S 2.6.0.1 via sprintf (remote)
CVE-2026-77004 5.3 - Medium - August 20, 2026

A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the file /cgi-bin/mbox-config?method=SET&section=ptest_sn. Executing a manipulation of the argument sn can lead to command injection. The attack can be launched remotely. The exploit has been published and may be used.

Command Injection

Stack Buffer Overflow in Comfast CF-N1-S 2.6.0.1 URI Parsing (get_para_from_uri)
CVE-2026-76008 10 - Critical - August 19, 2026

A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argument width/height causes stack-based buffer overflow. The attack can be initiated remotely.

Stack Overflow

COMFAST CF-N1-S 2.6.0.1 Remote Command Injection via CGI ssid
CVE-2026-75094 9.4 - Critical - August 18, 2026

A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component CGI Interface. This manipulation of the argument ssid causes os command injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.

Shell injection

COMFAST CF-N1-S 2.6.0.1 Command Injection via cgi-bin/mbox-config
CVE-2026-19976 5.1 - Medium - August 17, 2026

A security vulnerability has been detected in COMFAST CF-N1-S 2.6.0.1. Impacted is the function sub_44A968 of the file /cgi-bin/mbox-config?method=SET&section=ptest_macaddress. Such manipulation of the argument macaddress leads to command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Command Injection

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Comfast Cf N1 S or by Comfast? Click the Watch button to subscribe.

Comfast
Vendor

subscribe