Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-76008: Comfast CF-N1-S: Remote Code Execution via Malformed Image
CVE-2026-76008 · published 16 days ago
Summary
A security issue has been discovered in the Comfast CF-N1-S 2.6.0.1. This affects the way it handles certain image files. An attacker can potentially send a malicious image to the device, allowing them to execute unauthorized code. To protect your device, update to the latest version of the software.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| comfast | cf-n1-s | 2.6.0.1 |
Original advisory text
A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argum...
A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argument width/height causes stack-based buffer overflow. The attack can be initiated remotely.
References
- https://vuldb.com/vuln/391922 vdb-entry technical-description
- https://vuldb.com/vuln/391922/cti signature permissions-required
- https://vuldb.com/cve/CVE-2026-76008 third-party-advisory
- https://vuldb.com/submit/878007 third-party-advisory
- https://github.com/1ChaoRen1/IOT_3 related
Severity
10.0
Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS <1%
Type
CWE-121Stack-based Buffer Overflow
CWE-119Buffer Overflow
Timeline
Published19 Aug 2026
Updated3 Sep 2026
First seen19 Aug 2026
Monitor software like this
Free during beta