{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/cf-n1-s-2.6.0.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-75094"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CF-N1-S (2.6.0.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["COMFAST"],"content_html":"\u003cp\u003eA critical command injection vulnerability has been identified in the COMFAST CF-N1-S firmware version 2.6.0.1. The flaw exists within the CGI interface component, specifically affecting the function \u003ccode\u003esub_44B438\u003c/code\u003e located in the \u003ccode\u003e/cgi-bin/mbox-config\u003c/code\u003e endpoint. Attackers can trigger this vulnerability by manipulating the \u003ccode\u003essid\u003c/code\u003e argument when calling the \u003ccode\u003eSET\u003c/code\u003e method with the \u003ccode\u003eptest_ssid\u003c/code\u003e section.\u003c/p\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary operating system command execution with the privileges of the web service. The vulnerability is considered remote-exploitable, and proof-of-concept exploit code has been publicly disclosed. Given the nature of the device as networking equipment, this vulnerability poses a significant risk for persistent device compromise and lateral network movement. Defenders should prioritize identifying and restricting access to the administrative CGI interface for these devices.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify reachable COMFAST CF-N1-S web management interfaces.\u003c/li\u003e\n\u003cli\u003eAttacker obtains administrative credentials to access the target's CGI interface.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP request targeting \u003ccode\u003e/cgi-bin/mbox-config?method=SET\u0026amp;section=ptest_ssid\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker injects arbitrary OS commands into the \u003ccode\u003essid\u003c/code\u003e argument parameter within the POST request body or query string.\u003c/li\u003e\n\u003cli\u003eThe target's \u003ccode\u003esub_44B438\u003c/code\u003e function fails to sanitize the input, passing the concatenated string directly to a system shell execution process.\u003c/li\u003e\n\u003cli\u003eThe embedded OS executes the attacker-supplied commands.\u003c/li\u003e\n\u003cli\u003eAttacker establishes persistence or pivots into the internal network from the compromised networking device.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-75094 results in full remote code execution on the affected COMFAST CF-N1-S devices. An attacker could leverage this access to exfiltrate sensitive network traffic, intercept internal communications, or pivot to internal segments. As this affects network infrastructure, the impact extends to the integrity and confidentiality of the entire managed network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the following actions to mitigate the risk associated with CVE-2026-75094:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately restrict access to the web management interface of COMFAST CF-N1-S devices to trusted management IP ranges only.\u003c/li\u003e\n\u003cli\u003eDisable public-facing access to the device's CGI interface at the network perimeter.\u003c/li\u003e\n\u003cli\u003eReview network logs for HTTP POST requests directed at \u003ccode\u003e/cgi-bin/mbox-config\u003c/code\u003e containing unusual metacharacters (e.g., \u003ccode\u003e;\u003c/code\u003e, \u003ccode\u003e|\u003c/code\u003e, \u003ccode\u003e\u0026amp;\u003c/code\u003e, \u003ccode\u003e$\u003c/code\u003e) within the \u003ccode\u003essid\u003c/code\u003e parameter.\u003c/li\u003e\n\u003cli\u003eIf a firmware update is unavailable, isolate the device from the internet to prevent remote exploitation of this authenticated vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-18T02:52:43Z","date_published":"2026-08-18T02:52:43Z","id":"https://feed.craftedsignal.io/briefs/2026-08-comfast-cve-2026-75094/","summary":"A critical command injection vulnerability (CVE-2026-75094) in the COMFAST CF-N1-S CGI interface allows remote, authenticated attackers to execute arbitrary OS commands via the 'ssid' parameter.","title":"Command Injection Vulnerability in COMFAST CF-N1-S","url":"https://feed.craftedsignal.io/briefs/2026-08-comfast-cve-2026-75094/"}],"language":"en","title":"CraftedSignal Threat Feed - CF-N1-S (2.6.0.1)","version":"https://jsonfeed.org/version/1.1"}