CVE-2026-2534Disclosure(comfast / cf-n1)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch comfast cf-n1 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability has been found in Comfast CF-N1 V2 2.6.0.2. The affected element is the function sub_44AC4C of the file /cgi-bin/mbox-config?method=SET&section=ptest_bandwidth. The manipulation of the argument bandwidth leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cf-n1
  • cf-n1_firmware

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 4 mentions (2026-02-16); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
cf-n1cf-n1_firmware

2 versions affected across 2 products

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-02-16: 4Mentions · 2026-02-18: 1Patch / Workaround · 2026-02-18: 1Technical Details · 2026-02-16: 4Technical Details · 2026-02-18: 102-1602-18
Signal classification1 categories
Disclosure
5100.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-02-164
Disclosure4
2026-02-181
Disclosure1
Full discourse5 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2534 Remote Command Injection in Comfast CF-N1 V2 2.6.0.2 via Bandwidth Config... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2534 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The text announces CVE-2026-2534, a remote command injection flaw in Comfast CF‑N1 routers, and provides links to vulnerability details and a notification.

    0002034
    4.0K followersView on X
  • NerdieNews@NewsNerdie
    Disclosure

    Today's Top Cybersecurity News – February 16, 2026 1. Multiple Stack Buffer Overflow Vulnerabilities in Bosch Infotainment ECU Bluetooth Stack Three distinct stack-based buffer overflow vulnerabilities (CVE-2025-32059, CVE-2025-32061, CVE-2025-32062) have been identified in the Bluetooth stack developed by Alps Alpine for Bosch Infotainment ECUs. These flaws allow remote attackers to execute arbitrary code via malformed packets on the L2CAP channel, posing significant risks to vehicle infotainment system security. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2025-32062 2. Critical Privilege Escalation and Account Takeover Vulnerabilities in JUNG eNet SMART HOME Server Multiple critical vulnerabilities in JUNG eNet SMART HOME server versions 2.2.1 and 2.3.1 allow low-privileged users to escalate privileges, reset passwords of admin accounts without authorization, and exploit default credentials to gain administrative access. These flaws expose smart home environments to unauthorized control and potential compromise. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-26369 3. Suspected Russian APT Deploys CANFAIL Malware Targeting Ukrainian Critical Sectors A newly identified Russia-linked APT group has deployed CANFAIL malware against Ukrainian defense, government, and energy organizations, posing significant risks to critical infrastructure. The attacks highlight ongoing geopolitical cyber threats and potential disruptions to national security and energy operations. Sources: Feedburner, Securityaffairs https://securityaffairs.com/187976/hacking/suspected-russian-hackers-deploy-canfail-malware-against-ukraine.html 4. CISA Alerts on Critical ZLAN ICS Flaws Allowing Full Device Takeover CISA has issued a critical advisory for severe vulnerabilities in ZLAN5143D serial-to-Ethernet device servers used in industrial control systems. These flaws enable attackers to gain full control over affected devices, risking disruption of critical infrastructure operations. Sources: Cvefeed, Gbhackers https://gbhackers.com/cisa-issues-alert-on-zlan-ics-flaws-enabling-full-device-takeover/ 5. Critical Command Injection Vulnerabilities in Comfast CF-N1 V2 Firmware Two remote command injection vulnerabilities (CVE-2026-2534 and CVE-2026-2535) affect Comfast CF-N1 V2 2.6.0.2 via the mbox-config CGI interface. Both exploits have been publicly disclosed and can be leveraged by attackers to execute arbitrary commands remotely. The vendor has not responded to early notifications, increasing the risk of widespread exploitation. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-2535 Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats

    Post summary

    The article lists several newly disclosed CVEs with technical details but provides no PoC, exploit code, active exploitation evidence, or patch information.

    0001034
    54 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2534 A vulnerability has been found in Comfast CF-N1 V2 2.6.0.2. The affected element is the function sub_44AC4C of the file /cgi-bin/mbox-config?method=SET&section=ptest_ba… https://www.cve.org/CVERecord?id=CVE-2026-2534

    Post summary

    A vulnerability CVE-2026-2534 was identified in Comfast CF-N1 V2 2.6.0.2, affecting the sub_44AC4C function in /cgi-bin/mbox-config, but no additional details such as PoC, exploit, or patch were disclosed.

    00010412
    56.4K followersView on X
  • Cybersecurity Aide@SecAideInfo
    Disclosure

    🚨 New CVE Alert: CVE-2026-2534 🛡️: A command injection flaw in Comfast CF-N1 V2 2.6.0.2 via /cgi-bin/mbox-config allows remote attacks! ⚠️ Vendors unresponsive—expect exploitation soon. Patch & protect now! 🛡️ #Cybersecurity #Infosec #CVE2026 #StaySafe

    Post summary

    The post announces a new command injection vulnerability (CVE-2026-2534) affecting Comfast CF‑N1 routers and urges users to apply patches before exploitation occurs.

    0000038
    20 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-2534 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-2534 #CVE-2026-2534 #CVE #Medium #CyberSecurity #InfoSec https://t.co/UbC02TWtXV

    Post summary

    The tweet announces CVE-2026-2534 with a CVSS score of 6.3 and indicates medium risk, but does not provide any proof‑of‑concept, exploit code, patch details, or evidence of active exploitation.

    0000045
    56 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWcomfastcf-n12--
OScomfastcf-n1_firmware2.6.0.2--

Explore more