Command Injection in Comfast CF-N1-S and CF-WR630AX Firmware
CVE-2026-75364
6.8MEDIUM
What is CVE-2026-75364?
The Comfast CF-N1-S and CF-WR630AX firmware contain a vulnerability in the update_interface_png SET handler located in /usr/bin/webmgnt. Due to inadequate sanitization of the display_name parameter, an attacker with authenticated access can manipulate user-controlled input. This input is concatenated into the unquoted shell command /etc/rrd/graphinterface %s %s, which is executed by the system with elevated privileges. This flaw allows remote authenticated attackers to execute arbitrary commands, potentially leading to further compromises of the network device.
