OS Command Injection in Comfast CF-WR631AX V3 Leading to Remote Exploit
CVE-2026-12814
Key Information:
- Vendor
Comfast
- Status
- Vendor
- CVE Published:
- 21 June 2026
Badges
What is CVE-2026-12814?
A security vulnerability in the Comfast CF-WR631AX V3 router impacts the API Endpoint due to improper handling of input parameters in the mbox-config system. An attacker can exploit this vulnerability to inject arbitrary OS commands remotely, leading to potential system compromise. Despite attempts to alert the vendor about this critical issue, there has been no response, and public exploit details are now available.
Affected Version(s)
CF-WR631AX V3 2.7.0.0
CF-WR631AX V3 2.7.0.1
CF-WR631AX V3 2.7.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
