cf-n1_firmware vulnerabilities
CVEs whose affected-version data names the cf-n1_firmware package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
6 CVEsRSS
CVE-2025-9586Medium· 6.3A vulnerability was identified in Comfast CF-N1 2.6.0
A vulnerability was identified in Comfast CF-N1 2.6.0. This vulnerability affects the function wireless_device_dissoc of the file /usr/bin/webmgnt. Such manipulation of the argument mac leads to command injection. The attack may be perfo…
CVE-2025-9585Medium· 6.3A vulnerability was determined in Comfast CF-N1 2.6.0
A vulnerability was determined in Comfast CF-N1 2.6.0. This affects the function wifilith_delete_pic_file of the file /usr/bin/webmgnt. This manipulation of the argument portal_delete_picname causes command injection. The attack is possi…
CVE-2025-9584Medium· 6.3A vulnerability was found in Comfast CF-N1 2.6.0
A vulnerability was found in Comfast CF-N1 2.6.0. Affected by this issue is the function update_interface_png of the file /usr/bin/webmgnt. The manipulation of the argument interface/display_name results in command injection. The attack …
CVE-2025-9583Medium· 6.3A vulnerability has been found in Comfast CF-N1 2.6.0
A vulnerability has been found in Comfast CF-N1 2.6.0. Affected by this vulnerability is the function ping_config of the file /usr/bin/webmgnt. The manipulation leads to command injection. Remote exploitation of the attack is possible. T…
CVE-2025-9582Medium· 6.3A flaw has been found in Comfast CF-N1 2.6.0
A flaw has been found in Comfast CF-N1 2.6.0. Affected is the function ntp_timezone of the file /usr/bin/webmgnt. Executing manipulation of the argument timestr can lead to command injection. The attack may be launched remotely. The expl…
CVE-2025-9581Medium· 6.3A vulnerability was detected in Comfast CF-N1 2.6.0
A vulnerability was detected in Comfast CF-N1 2.6.0. This impacts the function multi_pppoe of the file /usr/bin/webmgnt. Performing manipulation of the argument phy_interface results in command injection. The attack may be initiated remo…