Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-78050: Comfast CF-N1-S router allows remote code execution via web settings

CVE-2026-78050 · published 12 days ago
Summary

The web management page of the Comfast CF-N1-S router can be tricked into running unwanted code when an attacker sends a specially crafted request. This could let an attacker take control of the device from anywhere on the internet. Apply the latest firmware update from the vendor or disable the web management interface until it is patched.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
comfast cf-n1-s 2.6.0.1
Original advisory text
Comfast CF-N1-S Web Management mbox-config sub_41AD7C stack-based overflow
A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component Web Management. The manipulation of the argument timestr/ntp_client_enabled results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used.
References
Severity
8.6 High
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-121Stack-based Buffer Overflow
CWE-119Buffer Overflow
Timeline
Published22 Aug 2026
Updated3 Sep 2026
First seen22 Aug 2026
Sources
CVE-2026-78050 · MITRE
Monitor software like this
Free during beta