CVE-2026-75363: Comfast CF-WR630AX vulnerability
Published Aug 26, 2026
·Updated
An issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to execute arbitrary code via the /usr/bin/webmgnt, /cgi-bin/mbox-config, and the parameters timestr, displayn.
Affected Software
1 affected component
Comfast CF-WR630AX=2.7.0.2
Event History
Aug 26, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:16 PM
Description
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The issue is described as remotely exploitable. The available information does not state whether authentication or any specific network position is required.
2
Which interfaces and inputs are implicated?
The affected paths are /usr/bin/webmgnt and /cgi-bin/mbox-config. The parameters identified as attack inputs are timestr and display_n.
3
Which product version is confirmed affected?
Comfast CF-WR630AX version 2.7.0.2 is identified as affected. No fixed version or mitigation is provided in the available information.