Back

MEDIUM

Comfast CF-N1 webmgnt multi_pppoe command injection

Published Aug 28, 2025

Description

A vulnerability was detected in Comfast CF-N1 2.6.0. This impacts the function multi_pppoe of the file /usr/bin/webmgnt. Performing manipulation of the argument phy_interface results in command injection. The attack may be initiated remotely. The exploit is now public and may be used.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (2)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Aug 28, 2025
Updated Aug 28, 2025
Reserved Aug 28, 2025
CISA Vulnrichment
Updated Aug 28, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a