Stack-Based Buffer Overflow in Comfast CF-N1-S Affected by URI Parameter Manipulation
CVE-2026-76008
10CRITICAL
What is CVE-2026-76008?
A vulnerability exists in the Comfast CF-N1-S device where improper parsing of URI parameters in the mbox-config component allows remote attackers to exploit a stack-based buffer overflow. This flaw is triggered by manipulating the width and height arguments within the get_para_from_uri function, potentially leading to arbitrary code execution or a denial of service. It is crucial for users of this product to apply the necessary updates and mitigate risks associated with this vulnerability.
Affected Version(s)
CF-N1-S 2.6.0.1
