CVE-2026-77004

A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the file /cgi-bin/mbox-config?method=SET&section=ptest_sn. Executing a manipulation of the argument sn can lead to command injection. The attack can be launched remotely. The exploit has been published and may be used.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-20 16:18

Updated : 2026-08-24 16:40


NVD link : CVE-2026-77004

Mitre link : CVE-2026-77004

CVE.ORG link : CVE-2026-77004


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')