What is CVE-2026-19976?
A remote command injection vulnerability was found in COMFAST CF-N1-S 2.6.0.1, specifically in the `sub_44A968` function of `/cgi-bin/mbox-config`, by manipulating the `macaddress` argument. This could allow an attacker to execute arbitrary commands on the system. It is recommended to update the firmware or restrict network access.
Azərbaycanca: COMFAST CF-N1-S 2.6.0.1 cihazında `/cgi-bin/mbox-config` faylındakı `sub_44A968` funksiyasında `macaddress` parametrini manipulyasiya etməklə uzaqdan command injection zəifliyi aşkar edilmişdir. Bu, təcavüzkara sistemdə əmrlər icra etməyə imkan verə bilər. Cihaz proqram təminatını yeniləmək və ya şəbəkə girişini məhdudlaşdırmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
Which file and function in COMFAST CF-N1-S 2.6.0.1 are vulnerable to command injection?
The vulnerability was found in the `sub_44A968` function of the `/cgi-bin/mbox-config` file.
Which parameter must an attacker manipulate to exploit CVE-2026-19976?
An attacker can execute commands remotely by manipulating the `macaddress` argument.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.