Vulnerabilidad · Publicado 19/08/2026
Se ha identificado una falla de seguridad crítica (CVSS 10.0) en el dispositivo Comfast CF-N1-S versión 2.6.0.1 que afecta el procesamiento de parámetros URI en /cgi-bin/mbox-config. Un atacante remoto puede explotar un desbordamiento de búfer en la pila mediante manipulación de los parámetros width/height, comprometiendo completamente la integridad del dispositivo. Empresas en LATAM que utilicen estos puntos de acceso inalámbricos en infraestructura de oficinas o datos están en riesgo inmediato de intrusión no autorizada.
A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argument width/height causes stack-based buffer overflow. The attack can be initiated remotely.
Score: 10/10 — Severidad: CRITICAL — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-119, CWE-121
Publicado en NIST NVD.