MEDIUM
Comfast CF-N1-S Endpoint mbox-config command injection
Published Apr 21, 2026
5.3
MEDIUMCVSS 4.0
EPSS 2.38%
Description
A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is some unknown functionality of the file /cgi-bin/mbox-config?method=SET§ion=ping_config of the component Endpoint. Performing a manipulation of the argument destination results in command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
- Version 2.6.0.1StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24503 Advisory
- https://github.com/Blackhole23-Lab/-/blob/main/Comfast-CF-N1-S-Router-VUDB.md exploit
- https://vuldb.com/submit/795203 third-party-advisory
- https://vuldb.com/vuln/358492 vdb-entrytechnical-description
- https://vuldb.com/vuln/358492/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24503 | Advisory | |
| https://github.com/Blackhole23-Lab/-/blob/main/Comfast-CF-N1-S-Router-VUDB.md | exploit | |
| https://vuldb.com/submit/795203 | third-party-advisory | |
| https://vuldb.com/vuln/358492 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/358492/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Apr 21, 2026
Updated Apr 22, 2026
Reserved Apr 21, 2026
Link CVE-2026-6799
CISA Vulnrichment
Updated Apr 22, 2026
ENISA EUVD
EUVD-2026-24503 Assigner VulDB
Published Apr 21, 2026
Updated Apr 22, 2026
Exploited since n/a
Link EUVD-2026-24503