CVE-2026-4468: Comfast CF-AC100 mbox-config command injection
A vulnerability was determined in Comfast CF-AC100 2.6.0.8. Affected is an unknown function of the file /cgi-bin/mbox-config?method=SET§ion=updateinterfacepng. This manipulation causes command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4468?
CVE-2026-4468 has a high severity rating due to the potential for command injection vulnerabilities.
How do I fix CVE-2026-4468?
To remediate CVE-2026-4468, update the Comfast CF-AC100 to the latest version provided by the vendor.
What systems are affected by CVE-2026-4468?
CVE-2026-4468 affects the Comfast CF-AC100 with firmware version 2.6.0.8.
What kind of attack can be executed through CVE-2026-4468?
CVE-2026-4468 allows attackers to perform command injection through the mbox-config interface.
What is the impact of exploiting CVE-2026-4468?
Exploiting CVE-2026-4468 can lead to unauthorized command execution on the affected device.