VulnSea

comfast has 7 CVEs on record between 2025 and 2026. 1 was published in the last 90 days. The median CVSS is 6.3 (medium), with 1 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-74 (6) and CWE-77 (6). Most affected products: cf-n1_firmware (6), CF-N1-S (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.3
Publish → KEV
—
Last 90 days
1 prev 0

Products

  • cf-n1_firmware 6
  • CF-N1-S 1
7
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

comfast vulnerabilities

CVEs affecting comfast, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

CVE-2026-94003Critical· 10.0PoC
6d ago

A vulnerability has been found in Comfast CF-N1-S 2.6.0.1

A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config of the component Web Management Interface. The manipulation leads to stack-based buffer overflow. …

▾ AbyssalComfast · CF-N1-SEPSS 1.0%via NVD
CVE-2025-9586Medium· 6.3
1y ago

A vulnerability was identified in Comfast CF-N1 2.6.0

A vulnerability was identified in Comfast CF-N1 2.6.0. This vulnerability affects the function wireless_device_dissoc of the file /usr/bin/webmgnt. Such manipulation of the argument mac leads to command injection. The attack may be perfo…

▾ Sunlitcomfast · cf-n1_firmwareEPSS 8.3%via NVD
CVE-2025-9585Medium· 6.3
1y ago

A vulnerability was determined in Comfast CF-N1 2.6.0

A vulnerability was determined in Comfast CF-N1 2.6.0. This affects the function wifilith_delete_pic_file of the file /usr/bin/webmgnt. This manipulation of the argument portal_delete_picname causes command injection. The attack is possi…

▾ Sunlitcomfast · cf-n1_firmwareEPSS 5.1%via NVD
CVE-2025-9584Medium· 6.3
1y ago

A vulnerability was found in Comfast CF-N1 2.6.0

A vulnerability was found in Comfast CF-N1 2.6.0. Affected by this issue is the function update_interface_png of the file /usr/bin/webmgnt. The manipulation of the argument interface/display_name results in command injection. The attack …

▾ Sunlitcomfast · cf-n1_firmwareEPSS 8.3%via NVD
CVE-2025-9583Medium· 6.3
1y ago

A vulnerability has been found in Comfast CF-N1 2.6.0

A vulnerability has been found in Comfast CF-N1 2.6.0. Affected by this vulnerability is the function ping_config of the file /usr/bin/webmgnt. The manipulation leads to command injection. Remote exploitation of the attack is possible. T…

▾ Sunlitcomfast · cf-n1_firmwareEPSS 5.1%via NVD
CVE-2025-9582Medium· 6.3
1y ago

A flaw has been found in Comfast CF-N1 2.6.0

A flaw has been found in Comfast CF-N1 2.6.0. Affected is the function ntp_timezone of the file /usr/bin/webmgnt. Executing manipulation of the argument timestr can lead to command injection. The attack may be launched remotely. The expl…

▾ Sunlitcomfast · cf-n1_firmwareEPSS 5.3%via NVD
CVE-2025-9581Medium· 6.3
1y ago

A vulnerability was detected in Comfast CF-N1 2.6.0

A vulnerability was detected in Comfast CF-N1 2.6.0. This impacts the function multi_pppoe of the file /usr/bin/webmgnt. Performing manipulation of the argument phy_interface results in command injection. The attack may be initiated remo…

▾ Sunlitcomfast · cf-n1_firmwareEPSS 5.3%via NVD
comfast vulnerabilities (CVEs) · VulnSea