CVE-2026-76008: Comfast CF-N1-S URI Parameter Parsing mbox-config get_para_from_uri stack-based overflow
Published Aug 19, 2026
·Updated
A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function getparafromuri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argument width/height causes stack-based buffer overflow. The attack can be initiated remotely.
Affected Software
1 affected component
Comfast CF-N1-S=2.6.0.1
Event History
Aug 19, 2026
CVE Published
via MITRE·02:30 AM
Data Sourced
via MITRE·02:30 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which systems are known to be affected?
The affected product and version identified are Comfast CF-N1-S 2.6.0.1. The vulnerable code is in the /cgi-bin/mbox-config component's get_para_from_uri function.
2
Does exploitation require authentication or user interaction?
No authentication or user interaction is indicated. The vector is network-based with low attack complexity, and the issue can be initiated remotely.
3
What input is involved in triggering the overflow?
The stack-based buffer overflow is triggered through manipulation of the width and height arguments processed during URI parameter parsing.