Comfast CF-N1 Command Injection Vulnerability in Wireless Device Dissociation Function

Vulnerability

A command injection vulnerability has been identified in the Comfast CF-N1 V2 wireless router, specifically in version 2.6.0. The issue arises in the 'wireless_device_dissoc' function within the '/usr/bin/webmgnt' file. This vulnerability allows attackers to inject arbitrary commands through the 'mac' parameter, which is not properly sanitized before being executed. The flaw can be exploited remotely, potentially leading to unauthorized execution of system commands, access to sensitive information, or complete control over the device.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the device, with the potential to read sensitive files or gain full control over the router.

Reproduction

To reproduce this vulnerability, send a POST request to the '/cgi-bin/mbox-config' endpoint with the 'method' set to 'SET' and the 'section' set to 'wireless_device_dissoc'. Include a crafted 'mac' parameter that exploits the command injection flaw, such as one that uses command separators to inject and execute additional commands.

Added: Aug 28, 2025, 9:21 PM
Updated: Aug 28, 2025, 9:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
0.4
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.