VYPR

CF-WR630AX

by Comfast

CVEs (3)

  • CVE-2024-54751CriDec 10, 2024
    risk 0.64cvss 9.8epss 0.00

    COMFAST CF-WR630AX v2.7.0.2 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

  • CVE-2026-75364MedAug 26, 2026
    risk 0.44cvss 6.8epss 0.00

    Comfast CF-N1-S firmware 2.6.0.1 and CF-WR630AX (2024-01-30 build), the update_interface_png SET handler in /usr/bin/webmgnt fails to sanitize the display_name parameter. User-controlled input is concatenated via sprintf() into the unquoted shell command `/etc/rrd/graphinterface…

  • CVE-2026-75363MedAug 26, 2026
    risk 0.44cvss 6.8epss 0.00

    An issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to execute arbitrary code via the /usr/bin/webmgnt, /cgi-bin/mbox-config, and the parameters timestr, display_n.