PT-2025-35136 · Comfast · Comfast Cf-N1
N0Ps1Ed
·
Published
2025-08-28
·
Updated
2025-08-28
·
CVE-2025-9584
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Comfast CF-N1 version 2.6.0
Description
A vulnerability exists in Comfast CF-N1 version 2.6.0 due to command injection. The issue is located in the
update interface png function within the /usr/bin/webmgnt file. Manipulation of the interface/display name argument can lead to remote code execution. The exploit for this issue has been publicly disclosed.Recommendations
Update Comfast CF-N1 to a newer version that addresses this issue.
As a temporary workaround, restrict access to the
/usr/bin/webmgnt file.
Avoid using the interface/display name argument in the update interface png function until the issue is resolved.Exploit
Fix
Special Elements Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Comfast Cf-N1