CVE-2026-78050: Comfast CF-N1-S Web Management mbox-config sub_41AD7C stack-based overflow
Published Aug 22, 2026
·Updated
A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub41AD7C of the file /cgi-bin/mbox-config?method=SET§ion=ntptimezone of the component Web Management. The manipulation of the argument timestr/ntpclientenabled results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used.
Affected Software
1 affected component
Comfast CF-N1-S Web Management=2.6.0.1
Event History
Aug 22, 2026
CVE Published
via MITRE·11:15 PM
Data Sourced
via MITRE·11:15 PM
DescriptionSeverityWeakness
Aug 23, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attack vector is network-based and requires low privileges. No user interaction is required.
2
Which input paths are affected?
The vulnerable Web Management endpoint is /cgi-bin/mbox-config with method=SET and section=ntp_timezone. The affected arguments are timestr and ntp_client_enabled.
3
Is public exploit information available?
Yes. The exploit has been made public, which increases the likelihood of attempted exploitation.