CVE-2025-9586: Comfast CF-N1 webmgnt wireless_device_dissoc command injection
Published Aug 28, 2025
·Updated
A vulnerability was identified in Comfast CF-N1 2.6.0. This vulnerability affects the function wirelessdevicedissoc of the file /usr/bin/webmgnt. Such manipulation of the argument mac leads to command injection. The attack may be performed from a remote location. The exploit is publicly available and might be used.
Affected Software
3 affected components
Comfast CF-N1
All of the following
Comfast Cf-n1 Firmware=2.6.0
Comfast CF-N1=2
Event History
Aug 28, 2025
CVE Published
via MITRE·09:02 PM
Data Sourced
via MITRE·09:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Feb 28, 57989
Event
via FIRST·01:37 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-9586?
CVE-2025-9586 has a high severity due to its potential for remote command injection.
2
How do I fix CVE-2025-9586?
To fix CVE-2025-9586, update the firmware of Comfast CF-N1 to the latest version.
3
What type of vulnerability is CVE-2025-9586?
CVE-2025-9586 is classified as a command injection vulnerability.
4
Who is affected by CVE-2025-9586?
CVE-2025-9586 affects users of the Comfast CF-N1 version 2.6.0.
5
Can CVE-2025-9586 be exploited remotely?
Yes, CVE-2025-9586 can be exploited remotely by manipulating the mac argument.