CVE-2026-75364: Comfast CF-N1-S firmware vulnerability
Comfast CF-N1-S firmware 2.6.0.1 and CF-WR630AX (2024-01-30 build), the updateinterfacepng SET handler in /usr/bin/webmgnt fails to sanitize the displayname parameter. User-controlled input is concatenated via sprintf() into the unquoted shell command /etc/rrd/graphinterface %s %s and executed by system() with root privileges. A remote authenticated attacker can inject arbitrary commands
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Comfast CF-N1-S firmwareto a version that resolves this vulnerability.Fixed in 2.6.0.1 - Upgrade
Upgrade
Comfast CF-WR630AX firmwareto a version that resolves this vulnerability.Fixed in 2024-01-30 build - Compensating control
Restrict access to the affected web management endpoint that exposes the update_interface_png SET handler (in /usr/bin/webmgnt) to trusted users/IPs only, to prevent remote authenticated command injection.
Event History
Frequently Asked Questions
What level of access is required to exploit this issue?
An attacker must be remotely authenticated before exploiting the vulnerable handler.
What privileges can injected commands run with?
Injected commands are executed with root privileges through the affected firmware's web management process.
Which firmware releases are identified as affected?
The affected releases are Comfast CF-N1-S firmware 2.6.0.1 and Comfast CF-WR630AX firmware built on 2024-01-30.