Skip to content
Threat Feed
critical advisory

Command Injection Vulnerability in COMFAST CF-N1-S

A critical command injection vulnerability (CVE-2026-75094) in the COMFAST CF-N1-S CGI interface allows remote, authenticated attackers to execute arbitrary OS commands via the 'ssid' parameter.

CVE search metadata

CVE search record: CVE-2026-75094. Severity: critical. CVSS: 9.1. KEV: no. Product: CF-N1-S (2.6.0.1). Brief: Command Injection Vulnerability in COMFAST CF-N1-S. Brief link: https://feed.craftedsignal.io/briefs/2026-08-comfast-cve-2026-75094/

What's new

  • 1. added detection rule: Detect CVE-2026-78050 Exploitation Attempt Aug 23, 01:33 via nvd
  • 2. added detection rule: Detects CVE-2026-77022 Exploitation - Malicious SSID Parameter Aug 20, 19:18 via nvd

A critical command injection vulnerability has been identified in the COMFAST CF-N1-S firmware version 2.6.0.1. The flaw exists within the CGI interface component, specifically affecting the function sub_44B438 located in the /cgi-bin/mbox-config endpoint. Attackers can trigger this vulnerability by manipulating the ssid argument when calling the SET method with the ptest_ssid section.

Successful exploitation allows for arbitrary operating system command execution with the privileges of the web service. The vulnerability is considered remote-exploitable, and proof-of-concept exploit code has been publicly disclosed. Given the nature of the device as networking equipment, this vulnerability poses a significant risk for persistent device compromise and lateral network movement. Defenders should prioritize identifying and restricting access to the administrative CGI interface for these devices.

Attack Chain

  1. Attacker performs reconnaissance to identify reachable COMFAST CF-N1-S web management interfaces.
  2. Attacker obtains administrative credentials to access the target's CGI interface.
  3. Attacker crafts a malicious HTTP request targeting /cgi-bin/mbox-config?method=SET&section=ptest_ssid.
  4. Attacker injects arbitrary OS commands into the ssid argument parameter within the POST request body or query string.
  5. The target's sub_44B438 function fails to sanitize the input, passing the concatenated string directly to a system shell execution process.
  6. The embedded OS executes the attacker-supplied commands.
  7. Attacker establishes persistence or pivots into the internal network from the compromised networking device.

Impact

Successful exploitation of CVE-2026-75094 results in full remote code execution on the affected COMFAST CF-N1-S devices. An attacker could leverage this access to exfiltrate sensitive network traffic, intercept internal communications, or pivot to internal segments. As this affects network infrastructure, the impact extends to the integrity and confidentiality of the entire managed network.

Recommendation

Prioritize the following actions to mitigate the risk associated with CVE-2026-75094:

  • Immediately restrict access to the web management interface of COMFAST CF-N1-S devices to trusted management IP ranges only.
  • Disable public-facing access to the device's CGI interface at the network perimeter.
  • Review network logs for HTTP POST requests directed at /cgi-bin/mbox-config containing unusual metacharacters (e.g., ;, |, &, $) within the ssid parameter.
  • If a firmware update is unavailable, isolate the device from the internet to prevent remote exploitation of this authenticated vulnerability.

Immediate actions

Restrict access to CGI interfaces on COMFAST devices via firewalls

IT Operations 24h

Mitigations

Isolate COMFAST devices from the public internet

immediate IT Operations

CVE-2026-75094

Detection coverage 3

Detects CVE-2026-75094 Exploitation - Command Injection in COMFAST CF-N1-S

high

Detects attempts to inject OS commands into the 'ssid' parameter of the COMFAST CF-N1-S CGI interface via the mbox-config endpoint.

sigma tactics: execution, initial_access techniques: T1059 sources: webserver

Detects CVE-2026-77022 Exploitation - Malicious SSID Parameter

high

Detects potential exploitation attempts by monitoring HTTP requests to the configuration endpoint with suspicious 'ssid' parameter patterns or anomalous length.

sigma tactics: execution, initial_access techniques: T1059 sources: webserver

Detect CVE-2026-78050 Exploitation Attempt

critical

Detects exploitation attempts against CVE-2026-78050 by identifying requests to the mbox-config endpoint with suspicious input lengths.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →