Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-76008Desbordamiento de búfer en Comfast CF-N1-S

A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argument width/height causes stack-based buffer overflow. The attack can be initiated remotely.

Ver en NVD

Análisis

Una vulnerabilidad de desbordamiento de búfer en el firmware de Comfast CF-N1-S permite la ejecución remota de código mediante la manipulación de parámetros en la URI. Un atacante puede tomar control total del dispositivo enviando peticiones maliciosas a los parámetros de ancho y alto en el script mbox-config. Dada su puntuación CVSS 10.0, es crítico actualizar o restringir el acceso administrativo a estos dispositivos de red.

Roles relevantes

HardwareCyberSecurityCC++

Severidad

Puntaje: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-119CWE-121

EPSS

Sin puntaje EPSS aún (CVE muy reciente).

Descripción técnica

A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argument width/height causes stack-based buffer overflow. The attack can be initiated remotely.

Publicada: 19/8/2026, 3:16:53
Última modificación: 19/8/2026, 3:16:53

Referencias

InicioEventosBlogRecursosCursosEquipo