comfast has 7 CVEs on record between 2025 and 2026. 1 was published in the last 90 days. The median CVSS is 6.3 (medium), with 1 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-74 (6) and CWE-77 (6). Most affected products: cf-n1_firmware (6), CF-N1-S (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.3
- Publish → KEV
- —
- Last 90 days
- 1 prev 0
Worst active — by depth score
CVE-2026-94003Critical· 10.0A vulnerability has been found in Comfast CF-N1-S 2.6.0.167CVE-2025-9586Medium· 6.3A vulnerability was identified in Comfast CF-N1 2.6.036CVE-2025-9585Medium· 6.3A vulnerability was determined in Comfast CF-N1 2.6.036CVE-2025-9584Medium· 6.3A vulnerability was found in Comfast CF-N1 2.6.036CVE-2025-9583Medium· 6.3A vulnerability has been found in Comfast CF-N1 2.6.036
comfast vulnerabilities
CVEs affecting comfast, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
CVE-2026-94003Critical· 10.0PoCA vulnerability has been found in Comfast CF-N1-S 2.6.0.1
A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config of the component Web Management Interface. The manipulation leads to stack-based buffer overflow. …
CVE-2025-9586Medium· 6.3A vulnerability was identified in Comfast CF-N1 2.6.0
A vulnerability was identified in Comfast CF-N1 2.6.0. This vulnerability affects the function wireless_device_dissoc of the file /usr/bin/webmgnt. Such manipulation of the argument mac leads to command injection. The attack may be perfo…
CVE-2025-9585Medium· 6.3A vulnerability was determined in Comfast CF-N1 2.6.0
A vulnerability was determined in Comfast CF-N1 2.6.0. This affects the function wifilith_delete_pic_file of the file /usr/bin/webmgnt. This manipulation of the argument portal_delete_picname causes command injection. The attack is possi…
CVE-2025-9584Medium· 6.3A vulnerability was found in Comfast CF-N1 2.6.0
A vulnerability was found in Comfast CF-N1 2.6.0. Affected by this issue is the function update_interface_png of the file /usr/bin/webmgnt. The manipulation of the argument interface/display_name results in command injection. The attack …
CVE-2025-9583Medium· 6.3A vulnerability has been found in Comfast CF-N1 2.6.0
A vulnerability has been found in Comfast CF-N1 2.6.0. Affected by this vulnerability is the function ping_config of the file /usr/bin/webmgnt. The manipulation leads to command injection. Remote exploitation of the attack is possible. T…
CVE-2025-9582Medium· 6.3A flaw has been found in Comfast CF-N1 2.6.0
A flaw has been found in Comfast CF-N1 2.6.0. Affected is the function ntp_timezone of the file /usr/bin/webmgnt. Executing manipulation of the argument timestr can lead to command injection. The attack may be launched remotely. The expl…
CVE-2025-9581Medium· 6.3A vulnerability was detected in Comfast CF-N1 2.6.0
A vulnerability was detected in Comfast CF-N1 2.6.0. This impacts the function multi_pppoe of the file /usr/bin/webmgnt. Performing manipulation of the argument phy_interface results in command injection. The attack may be initiated remo…