PT-2025-38482 · Comfast · Cf-Xr11
Zz2266
·
Published
2025-09-18
·
Updated
2025-09-19
·
CVE-2025-57293
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
COMFAST CF-XR11 version V2.7.2
Description
A command injection issue exists in the multi pppoe API, processed by the
sub 423930 function. The phy interface parameter is not sanitized, allowing attackers to inject arbitrary commands via a POST request to /cgi-bin/mbox-config?method=SET§ion=multi pppoe. Specifically, when the action parameter is set to "one click redial", the unsanitized phy interface is used in a system() call, enabling execution of malicious commands. This can lead to unauthorized access to sensitive files, execution of arbitrary code, or full device compromise.Recommendations
As a temporary workaround, consider disabling the multi pppoe API until a patch is available.
Restrict access to the
/cgi-bin/mbox-config endpoint to minimize the risk of exploitation.
Avoid using the action parameter with the value "one click redial" until the issue is resolved.Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cf-Xr11