CVE-2026-12814Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in Comfast CF-WR631AX V3 up to 2.7.0.8. This issue affects the function system of the file /cgi-bin/mbox-config?section=ping_config of the component API Endpoint. This manipulation of the argument destination causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-06-22)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-21: 1Mentions · 2026-06-22: 2Technical Details · 2026-06-21: 106-2106-22
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-211
Disclosure1
2026-06-222
Disclosure1General1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-12814 A flaw has been found in Comfast CF-WR631AX V3 up to 2.7.0.8. This issue affects the function system of the file /cgi-bin/mbox-config?section=ping_config of the compo… https://www.cve.org/CVERecord?id=CVE-2026-12814 ----- Traducción: Se encontró una fa… http://infoflow.cloud`

    Post summary

    A new CVE (2026-12814) affecting a Comfast router firmware is disclosed, but the snippet provides minimal technical detail and no information on exploitation, mitigation, or patches.

    0000065
    88 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-12814 A flaw has been found in Comfast CF-WR631AX V3 up to 2.7.0.8. This issue affects the function system of the file /cgi-bin/mbox-config?section=ping_config of the compo… https://www.cve.org/CVERecord?id=CVE-2026-12814

    Post summary

    The text announces a flaw in Comfast CF‑WR631AX devices affecting a CGI function, but provides no evidence of exploitation, POC, patches, or detailed technical classification.

    00000904
    57.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-12814 Remote OS Command Injection in Comfast CF-WR631AX V3 Up To 2.7.0.8 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-12814

    Post summary

    A remote OS command injection vulnerability (CVE-2026-12814) affecting Comfast CF-WR631AX V3 up to firmware 2.7.0.8 has been disclosed, but no PoC, exploit, or patch details are provided.

    00000122
    4.1K followersView on X

Explore more