{"apiVersion":"1.0","identifier":"CVE-2026-75364","description":"Comfast CF-N1-S firmware 2.6.0.1 and CF-WR630AX (2024-01-30 build), the update_interface_png SET handler in /usr/bin/webmgnt fails to sanitize the display_name parameter. User-controlled input is concatenated via sprintf() into the unquoted shell command `/etc/rrd/graphinterface %s %s` and executed by system() with root privileges. A remote authenticated attacker can inject arbitrary commands","publishedAt":"2026-08-26T21:16:40","lastModifiedAt":"2026-08-26T21:16:40","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-75364","cvssScore":null,"cvssVector":"Pending","epssProbability":0.00169,"riskScore":0,"affectedProduct":"Comfast","affectedVersions":"unknown","vulnerabilityType":"Firmware","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-75364","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-75364","en":"https://www.redsauce.net/en/cves/CVE-2026-75364","fr":"https://www.redsauce.net/fr/cves/CVE-2026-75364","pt":"https://www.redsauce.net/pt/cves/CVE-2026-75364","de":"https://www.redsauce.net/de/cves/CVE-2026-75364","sk":"https://www.redsauce.net/sk/cves/CVE-2026-75364","el":"https://www.redsauce.net/el/cves/CVE-2026-75364"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-75364"}}