CVE-2025-9581: Comfast CF-N1 webmgnt multi_pppoe command injection
A vulnerability was detected in Comfast CF-N1 2.6.0. This impacts the function multipppoe of the file /usr/bin/webmgnt. Performing manipulation of the argument phyinterface results in command injection. The attack may be initiated remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9581?
CVE-2025-9581 is classified as a high severity vulnerability due to the potential for remote command injection.
How do I fix CVE-2025-9581?
To fix CVE-2025-9581, update the Comfast CF-N1 firmware to the latest version that addresses this vulnerability.
What is the impact of CVE-2025-9581?
The impact of CVE-2025-9581 is that an attacker can execute arbitrary commands on the affected device remotely.
Who is affected by CVE-2025-9581?
CVE-2025-9581 affects users of Comfast CF-N1 devices running version 2.6.0.
Can CVE-2025-9581 be exploited remotely?
Yes, CVE-2025-9581 can be exploited remotely by manipulating the argument phy_interface.