Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-77022: Comfast CF-N1-S router remote code risk via SSID setting

CVE-2026-77022 · published 14 days ago
Summary

The wireless router model Comfast CF-N1-S can be attacked from the network by sending a specially crafted Wi‑Fi name (SSID) to its configuration page. This triggers a memory error that could let an attacker run their own code on the device. Apply the latest firmware update from the vendor as soon as possible to close the problem.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
comfast cf-n1-s 2.6.0.1
Original advisory text
A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component SSI...
A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component SSID Configuration. The manipulation of the argument ssid results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
References
Severity
8.6 High
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-121Stack-based Buffer Overflow
CWE-119Buffer Overflow
Timeline
Published20 Aug 2026
Updated3 Sep 2026
First seen20 Aug 2026
Sources
CVE-2026-77022 · MITRE
Monitor software like this
Free during beta