Command Injection Vulnerability in Comfast CF-N1 Wireless Device Management
CVE-2025-9586
Key Information:
Badges
What is CVE-2025-9586?
A command injection vulnerability exists in the wireless_management function of the Comfast CF-N1 product, specifically in version 2.6.0. This issue arises from improper handling of user input in the management interface, which allows attackers to manipulate the MAC address input parameter. Exploitation can enable a remote attacker to execute arbitrary commands with elevated privileges, posing a significant risk to the network's integrity and security. Public exploit information has made this vulnerability a tangible threat that organizations should address promptly.
Affected Version(s)
CF-N1 2.6.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved