PT-2026-8314 · Comfast · Comfast Cf-E4

Cha0Yang

·

Published

2026-02-16

·

Updated

2026-02-16

·

CVE-2026-2537

CVSS v2.0
5.8
VectorAV:N/AC:L/Au:M/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Comfast CF-E4 version 2.6.0.1
Description A flaw exists in Comfast CF-E4 that allows for remote command injection. The issue is located within the HTTP POST Request Handler component, specifically in the file
/cgi-bin/mbox-config?method=SET&section=ntp timezone
. Manipulation of the
timestr
argument can lead to unauthorized command execution. The exploit for this issue is publicly available. The vendor was contacted regarding this disclosure but did not provide a response.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-2537

Affected Products

Comfast Cf-E4