CVE-2026-2535Disclosure(comfast / cf-n1)

LOWCVSS 8.8 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in Comfast CF-N1 V2 2.6.0.2. The impacted element is the function sub_44AB9C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel. The manipulation of the argument channel results in command injection. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-77

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cf-n1
  • cf-n1_firmware

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
cf-n1cf-n1_firmware

2 versions affected across 2 products

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-02-16: 4Technical Details · 2026-02-16: 302-16
Signal classification1 categories
Disclosure
4100.0%
Referenced assets8 URLs
Full discourse4 posts
  • NerdieNews@NewsNerdie
    Disclosure

    Today's Top Cybersecurity News – February 16, 2026 1. Multiple Stack Buffer Overflow Vulnerabilities in Bosch Infotainment ECU Bluetooth Stack Three distinct stack-based buffer overflow vulnerabilities (CVE-2025-32059, CVE-2025-32061, CVE-2025-32062) have been identified in the Bluetooth stack developed by Alps Alpine for Bosch Infotainment ECUs. These flaws allow remote attackers to execute arbitrary code via malformed packets on the L2CAP channel, posing significant risks to vehicle infotainment system security. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2025-32062 2. Critical Privilege Escalation and Account Takeover Vulnerabilities in JUNG eNet SMART HOME Server Multiple critical vulnerabilities in JUNG eNet SMART HOME server versions 2.2.1 and 2.3.1 allow low-privileged users to escalate privileges, reset passwords of admin accounts without authorization, and exploit default credentials to gain administrative access. These flaws expose smart home environments to unauthorized control and potential compromise. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-26369 3. Suspected Russian APT Deploys CANFAIL Malware Targeting Ukrainian Critical Sectors A newly identified Russia-linked APT group has deployed CANFAIL malware against Ukrainian defense, government, and energy organizations, posing significant risks to critical infrastructure. The attacks highlight ongoing geopolitical cyber threats and potential disruptions to national security and energy operations. Sources: Feedburner, Securityaffairs https://securityaffairs.com/187976/hacking/suspected-russian-hackers-deploy-canfail-malware-against-ukraine.html 4. CISA Alerts on Critical ZLAN ICS Flaws Allowing Full Device Takeover CISA has issued a critical advisory for severe vulnerabilities in ZLAN5143D serial-to-Ethernet device servers used in industrial control systems. These flaws enable attackers to gain full control over affected devices, risking disruption of critical infrastructure operations. Sources: Cvefeed, Gbhackers https://gbhackers.com/cisa-issues-alert-on-zlan-ics-flaws-enabling-full-device-takeover/ 5. Critical Command Injection Vulnerabilities in Comfast CF-N1 V2 Firmware Two remote command injection vulnerabilities (CVE-2026-2534 and CVE-2026-2535) affect Comfast CF-N1 V2 2.6.0.2 via the mbox-config CGI interface. Both exploits have been publicly disclosed and can be leveraged by attackers to execute arbitrary commands remotely. The vendor has not responded to early notifications, increasing the risk of widespread exploitation. Sources: Cvefeed https://cvefeed.io/vuln/detail/CVE-2026-2535 Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats

    Post summary

    The article announces several newly discovered vulnerabilities across automotive, smart‑home, and industrial control systems, detailing their technical aspects without reporting active exploitation, PoCs, or patches.

    0001034
    54 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2535 A vulnerability was found in Comfast CF-N1 V2 2.6.0.2. The impacted element is the function sub_44AB9C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel… https://www.cve.org/CVERecord?id=CVE-2026-2535

    Post summary

    A vulnerability in Comfast CF-N1 V2 2.6.0.2 was identified, affecting the function sub_44AB9C in /cgi-bin/mbox-config, with no exploit or patch details provided.

    00010371
    56.4K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-2535 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-2535 #CVE-2026-2535 #CVE #Medium #CyberSecurity #InfoSec https://t.co/f89aAMxi8H

    Post summary

    An alert for CVE-2026-2535 is posted with a medium severity of 6.3 and unspecified affected products, but no technical, exploit, or patch details are provided.

    0000045
    56 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2535 Command Injection Vulnerability in Comfast CF-N1 V2 Router via Channel Parameter https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2535

    Post summary

    The entry announces CVE‑2026‑2535 as a command‑injection flaw in the Comfast CF‑N1 V2 router, providing the vulnerability type and affected device but no PoC, exploit code, or patch information.

    0000035
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWcomfastcf-n12--
OScomfastcf-n1_firmware2.6.0.2--

Explore more