Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-77148: Comfast CF-N1-S router web setup can be crashed remotely

CVE-2026-77148 · published 14 days ago
Summary

The web‑based management interface on Comfast CF‑N1‑S routers (firmware version 2.6.0.1) has a coding mistake that can let an attacker send specially crafted data and overflow the device’s memory. This could cause the router to stop working or allow further attacks from a distance. Update the router firmware to the latest version or disable the web management feature until the patch is applied.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
comfast cf-n1-s 2.6.0.1
Original advisory text
A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel of the component Web Management. The man...
A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel of the component Web Management. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.
References
Severity
8.6 High
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-121Stack-based Buffer Overflow
CWE-119Buffer Overflow
Timeline
Published20 Aug 2026
Updated3 Sep 2026
First seen20 Aug 2026
Sources
CVE-2026-77148 · MITRE
Monitor software like this
Free during beta