A critical vulnerability, CVE-2026-76008, has been identified in Comfast CF-N1-S version 2.6.0.1. The flaw resides in the get_para_from_uri function within the /cgi-bin/mbox-config component, which improperly handles URI parameters, leading to a stack-based buffer overflow. This allows a remote attacker to manipulate the width/height arguments, triggering the overflow and potentially enabling arbitrary code execution. The vulnerability is remotely exploitable without authentication, posing a significant risk to systems using this appliance. Affected devices are at high risk of compromise, as exploitation could lead to full system control. Organizations deploying the Comfast CF-N1-S should immediately apply the latest vendor-provided patches to mitigate this risk. Until patched, administrators are advised to disable or restrict access to the vulnerable URI endpoint to prevent exploitation. This vulnerability underscores the importance of timely patch management for network appliances.
CRITICAL
CVSS 10.0
CVE-2026-76008
2026-08-20
Critical Remote Code Execution Vulnerability in Comfast CF-N1-S (CVE-2026-76008)
A critical vulnerability in Comfast CF-N1-S 2.6.0.1 allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the get_para_from_uri function.