Vulnerabilidad · Publicado 20/09/2026
Se ha identificado una vulnerabilidad crítica (CVSS 10.0) en los routers Comfast CF-N1-S versión 2.6.0.1 que afecta la interfaz web de gestión. Un desbordamiento de búfer en la función get_css_path_from_uri del archivo /cgi-bin/mbox-config permite a atacantes remotos ejecutar código arbitrario sin autenticación. La vulnerabilidad ha sido divulgada públicamente y explotada activamente.
A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config of the component Web Management Interface. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Score: 10/10 — Severidad: CRITICAL — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-119, CWE-121
Publicado en NIST NVD.