Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.6
CVE-2026-77148: Comfast CF-N1-S router web setup can be crashed remotely
CVE-2026-77148 · published 14 days ago
Summary
The web‑based management interface on Comfast CF‑N1‑S routers (firmware version 2.6.0.1) has a coding mistake that can let an attacker send specially crafted data and overflow the device’s memory. This could cause the router to stop working or allow further attacks from a distance. Update the router firmware to the latest version or disable the web management feature until the patch is applied.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| comfast | cf-n1-s | 2.6.0.1 |
Original advisory text
A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET§ion=ptest_channel of the component Web Management. The man...
A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET§ion=ptest_channel of the component Web Management. The manipulation results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been made public and could be used.
References
- https://vuldb.com/vuln/393733 vdb-entry technical-description
- https://vuldb.com/vuln/393733/cti signature permissions-required
- https://vuldb.com/cve/CVE-2026-77148 third-party-advisory
- https://vuldb.com/submit/880910 third-party-advisory
- https://github.com/AdminSafe/CVE/issues/7 exploit issue-tracking
Severity
8.6
High
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-121Stack-based Buffer Overflow
CWE-119Buffer Overflow
Timeline
Published20 Aug 2026
Updated3 Sep 2026
First seen20 Aug 2026
Monitor software like this
Free during beta