Description
A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argument width/height causes stack-based buffer overflow. The attack can be initiated remotely.
CVSS 10EPSS 0.5740000000000001%Risk 1.05
View source- Published
- 2026-08-19 03:16:53
- Affected versions
- ==2.6.0.1
- Type
- Firmware
- Last modified
- 2026-08-20 12:48:10
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H