CVE-2026-77004: Comfast CF-N1-S mbox-config sprintf command injection
Published Aug 20, 2026
·Updated
A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the file /cgi-bin/mbox-config?method=SET§ion=ptestsn. Executing a manipulation of the argument sn can lead to command injection. The attack can be launched remotely. The exploit has been published and may be used.
Affected Software
1 affected component
Comfast CF-N1-S=2.6.0.1
Event History
Aug 20, 2026
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The vulnerability is remotely exploitable and requires low-level privileges. No user interaction is required.
2
Which endpoint and input should defenders prioritize for monitoring or filtering?
The affected path is /cgi-bin/mbox-config with method=SET and section=ptest_sn. The command-injection manipulation is performed through the sn argument.
3
How likely is exploitation in the near term?
An exploit has been published and may be used. This makes exposed devices a higher priority for remediation and monitoring.