Vendor
critical
advisory
Command Injection Vulnerability in COMFAST CF-N1-S
3 rules 2 TTPs 1 CVEA critical command injection vulnerability (CVE-2026-75094) in the COMFAST CF-N1-S CGI interface allows remote, authenticated attackers to execute arbitrary OS commands via the 'ssid' parameter.
CF-N1-S
vulnerability
rce
network-infrastructure
3r
2t
1c
updated
critical
advisory
Comfast Router CVE-2026-15511: Remote OS Command Injection
1 rule 2 TTPs 1 CVEA critical remote OS command injection vulnerability, CVE-2026-15511, affects Comfast CF-WR631AX V3 WiFi routers, allowing unauthenticated remote attackers to execute arbitrary operating system commands by manipulating the 'filename' argument in the FastCGI Backend's file upload function, leading to full device compromise.
CF-WR631AX V3
vulnerability
command-injection
rce
firmware
router
fastcgi
1r
2t
1c