PT-2025-35136 · Comfast · Comfast Cf-N1

·

CVE-2025-9584

·

Published

2025-08-28

·

Updated

2025-08-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Comfast CF-N1 version 2.6.0
Description A vulnerability exists in Comfast CF-N1 version 2.6.0 due to command injection. The issue is located in the update interface png function within the /usr/bin/webmgnt file. Manipulation of the interface/display name argument can lead to remote code execution. The exploit for this issue has been publicly disclosed.
Recommendations Update Comfast CF-N1 to a newer version that addresses this issue. As a temporary workaround, restrict access to the /usr/bin/webmgnt file. Avoid using the interface/display name argument in the update interface png function until the issue is resolved.

Exploit

Fix

Special Elements Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-9584

Affected Products

Comfast Cf-N1