CVE-2026-75094

A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component CGI Interface. This manipulation of the argument ssid causes os command injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-18 02:17

Updated : 2026-08-20 12:48


NVD link : CVE-2026-75094

Mitre link : CVE-2026-75094

CVE.ORG link : CVE-2026-75094


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')