CVE-2026-76008Desbordamiento de búfer en Comfast CF-N1-S
A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argument width/height causes stack-based buffer overflow. The attack can be initiated remotely.
Ver en NVDAnálisis
Una vulnerabilidad de desbordamiento de búfer en el firmware de Comfast CF-N1-S permite la ejecución remota de código mediante la manipulación de parámetros en la URI. Un atacante puede tomar control total del dispositivo enviando peticiones maliciosas a los parámetros de ancho y alto en el script mbox-config. Dada su puntuación CVSS 10.0, es crítico actualizar o restringir el acceso administrativo a estos dispositivos de red.
Roles relevantes
Severidad
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCWE-119CWE-121EPSS
Sin puntaje EPSS aún (CVE muy reciente).
Descripción técnica
A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argument width/height causes stack-based buffer overflow. The attack can be initiated remotely.