What is CVE-2026-75094?
An OS command injection vulnerability was found in the CGI interface of COMFAST CF-N1-S version 2.6.0.1. Remote exploitation is possible due to improper validation of the `ssid` argument in `/cgi-bin/mbox-config` requests. This allows attackers to execute arbitrary commands on the system; the device should be immediately isolated from the network.
Azərbaycanca: COMFAST CF-N1-S 2.6.0.1 cihazında CGI interfeysində OS command injection zəifliyi aşkar edilib. Uzaqdan istismar mümkündür, çünki `/cgi-bin/mbox-config` sorğusunda `ssid` parametri düzgün yoxlanılmır. Bu, təcavüzkara sistemdə əmrlər icra etməyə imkan verir; cihaz dərhal şəbəkədən təcrid olunmalıdır.
Related CVEs
link basis: same weakness class CWE-78
FAQ2
Which version of my COMFAST CF-N1-S device is vulnerable to this OS command injection?
This vulnerability was found specifically in version 2.6.0.1 of the COMFAST CF-N1-S device. It is recommended to check if your device is running this version.
How can this security flaw be exploited remotely?
Remote exploitation is possible because the `ssid` parameter in requests to `/cgi-bin/mbox-config` is not properly validated. An attacker can use this parameter to execute arbitrary commands on the system.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.