Command Injection Vulnerability in Comfast CF-N1 by Comfast
CVE-2025-9581
Key Information:
Badges
What is CVE-2025-9581?
A significant command injection vulnerability has been identified in the Comfast CF-N1 2.6.0 device, specifically within the multi_pppoe function of the web management interface located at /usr/bin/webmgnt. This weakness allows attackers to manipulate the phy_interface argument, potentially enabling unauthorized command execution on the affected system. The vulnerability can be exploited remotely, posing a risk to network integrity and security. It is crucial for users and administrators to be aware of this vulnerability and take necessary precautions to mitigate potential attacks.
Affected Version(s)
CF-N1 2.6.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved