PT-2026-8310 · Comfast · Comfast Cf-N1 V2
Allanp0E
·
Publicado
2026-02-16
·
Atualizado
2026-02-18
·
CVE-2026-2534
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Comfast CF-N1 V2 version 2.6.0.2
Description
A remote command injection issue exists in Comfast CF-N1 V2 2.6.0.2. The issue is located in the
sub 44AC4C function within the /cgi-bin/mbox-config file. Manipulation of the bandwidth argument in the 'ptest bandwidth' section of the file allows for remote code execution. The exploit for this issue has been publicly disclosed. The vendor was notified but did not respond.Recommendations
For Comfast CF-N1 V2 version 2.6.0.2, as a temporary workaround, consider restricting access to the
/cgi-bin/mbox-config file to minimize the risk of exploitation. Avoid using the bandwidth parameter in the affected API endpoint /cgi-bin/mbox-config?method=SET§ion=ptest bandwidth until the issue is resolved.Exploit
Correção
Command Injection
Special Elements Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Comfast Cf-N1 V2