Comfast CF-AC100 Command Injection Vulnerability

Vulnerability

A command injection vulnerability exists in the Comfast CF-AC100 router running firmware version 2.6.0.8. The issue arises in the '/cgi-bin/mbox-config?method=SET&section=wireless_device_dissoc' endpoint, where the 'mac' parameter is not properly validated. This flaw allows remote attackers to execute arbitrary commands by sending crafted HTTP POST requests. Exploitation requires the attacker to log in and obtain session cookies.

Impact

Successful exploitation allows for arbitrary command execution on the device.

Reproduction

To reproduce this vulnerability, send a POST request to '/cgi-bin/mbox-config?method=SET&section=wireless_device_dissoc' with a crafted 'mac' parameter that includes the desired command. Ensure to include the necessary cookies for an active session.

Added: Mar 20, 2026, 3:26 AM
Updated: Mar 20, 2026, 3:26 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.6
remediation
0.0
relevance
4.2
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.