rootpwn

critical · CVSS v3 10 · CVSS v4 10

CVE-2026-94003

A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /c…

Description

A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config of the component Web Management Interface. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

Scores

Severity
critical
CVSS v2
10
CVSS v3
10
CVSS v4
10
EPSS

← All CVEs