Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.6
CVE-2026-77683: Comfast CF-N1-S router allows remote command execution
CVE-2026-77683 · published 13 days ago
Summary
The CF-N1-S device’s web configuration page can be tricked into running any command the attacker provides. This can be done over the network without needing physical access, potentially letting attackers take control of the router. Apply the vendor’s update or disable the vulnerable web function until a patch is installed.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| comfast | cf-n1-s | 2.6.0.1 |
Original advisory text
Comfast CF-N1-S mbox-config system command injection
A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method=SET§ion=ntp_timezone. The manipulation of the argument timestr results in command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Severity
8.6
High
CVSS 2.0: 9.0 (NVD)
CVSS 3.1: 9.9 (NVD)
CVSS 4.0: 8.6 (NVD)
Exploitation
EPSS 2%
Type
CWE-74Injection
CWE-77Command Injection
Timeline
Published21 Aug 2026
Updated30 Aug 2026
First seen21 Aug 2026
Monitor software like this
Free during beta