VYPR
Vendor

Comfast

Products
19
CVEs
45
Across products
68
Status
Private

Products

19

Recent CVEs

45
View all 45 CVEs →
  • CVE-2026-94003CriSep 20, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config of the component Web Management Interface. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The…

  • CVE-2026-76008CriAug 19, 2026
    risk 0.65cvss 10.0epss 0.01

    A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argument width/height causes stack-based buffer overflow. The attack can be initiated…

  • CVE-2024-44466CriSep 11, 2024
    risk 0.65cvss 9.8epss 0.11

    COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter iface.

  • CVE-2026-78050CriAug 23, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component Web Management. The manipulation of the argument timestr/ntp_client_enabled results in…

  • CVE-2026-77683CriAug 21, 2026
    risk 0.64cvss 9.9epss 0.03

    A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone. The manipulation of the argument timestr results in command injection. The attack can be launched…

  • CVE-2026-77148CriAug 20, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel of the component Web Management. The manipulation results in stack-based buffer overflow. The attack can be launched…

  • CVE-2026-77022CriAug 20, 2026
    risk 0.64cvss 9.9epss 0.01

    A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component SSID Configuration. The manipulation of the argument ssid results in stack-based…

  • CVE-2024-54751CriDec 10, 2024
    risk 0.64cvss 9.8epss 0.00

    COMFAST CF-WR630AX v2.7.0.2 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

  • CVE-2023-38866CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.02

    COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter interface and display_name.

  • CVE-2023-38864CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protal_delete_picname parameter in the sub_41171C function at bin/webmgnt.

  • CVE-2023-38865CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.02

    COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter timestr.

  • CVE-2023-38863CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the ifname and mac parameters in the sub_410074 function at bin/webmgnt.

  • CVE-2023-38862CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the destination parameter of sub_431F64 function in bin/webmgnt.

  • CVE-2022-47699CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.01

    COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 is vulnerable to Incorrect Access Control.

  • CVE-2022-47697CriJan 31, 2023
    risk 0.64cvss 9.8epss 0.01

    COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerable to Account takeover. Anyone can reset the password of the admin accounts.

  • CVE-2026-75094CriAug 18, 2026
    risk 0.59cvss 9.1epss 0.03

    A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component CGI Interface. This manipulation of the argument ssid causes os command injection. Remote exploitation of the…

  • CVE-2022-45725HigFeb 13, 2023
    risk 0.58cvss 8.8epss 0.07

    Improper Input Validation in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to execute arbitrary code on the target via an HTTP POST request

  • CVE-2025-57293HigSep 18, 2025
    risk 0.57cvss 8.8epss 0.02

    A command injection vulnerability in COMFAST CF-XR11 (firmware V2.7.2) exists in the multi_pppoe API, processed by the sub_423930 function in /usr/bin/webmgnt. The phy_interface parameter is not sanitized, allowing attackers to inject arbitrary commands via a POST request to…

  • CVE-2023-30310HigMay 28, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue discovered in Comfast Comfast CF-616AC routers allows attackers to hijack TCP sessions which could lead to a denial of service.

  • CVE-2022-47700HigJan 31, 2023
    risk 0.49cvss 7.5epss 0.01

    COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerable to Incorrect Access Control. Improper authentication allows requests to be made to back-end scripts without a valid session or authentication.