What is CVE-2026-76008?
A stack-based buffer overflow vulnerability has been identified in the get_para_from_uri function of /cgi-bin/mbox-config in Comfast CF-N1-S 2.6.0.1, triggered by manipulating width/height arguments. This remote flaw could allow code execution; users should restrict network access to the device until a patch is released.
Azərbaycanca: Comfast CF-N1-S 2.6.0.1 cihazının /cgi-bin/mbox-config faylındakı get_para_from_uri funksiyasında, width/height parametrlərinin işlənməsi zamanı stack-based buffer overflow zəifliyi aşkar edilib. Bu uzaqdan kod icrasına yol aça bilər. Cihaz sahibləri istehsalçıdan yamaq təmin olunana qədər cihazın internetə açıq interfeyslərini məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
What version of the Comfast CF-N1-S device is affected by CVE-2026-76008?
The vulnerability affects version 2.6.0.1 of the Comfast CF-N1-S device.
What temporary mitigation is recommended for CVE-2026-76008 until a patch is released?
Users should restrict network access to the device's exposed interfaces until a patch is released by the manufacturer.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.