CVE-2026-75094Disclosure

LOWCVSS 8.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component CGI Interface. This manipulation of the argument ssid causes os command injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-18: 3Technical Details · 2026-08-18: 308-18
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-75094 A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component… https://www.cve.org/CVERecord?id=CVE-2026-75094

    Post summary

    A vulnerability identified as CVE-2026-75094 affects a function in COMFAST CF-N1-S 2.6.0.1's web interface component; no PoC, exploit, active exploitation, or remediation details are provided.

    00000621
    58.0K followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    CyberSec Daily ✓ · 📡 Network Security · August 18, 2026 🎯 Critical COMFAST appliance vulnerability published with a 9.1 severity score A new vulnerability tracked as CVE-2026-75094 has been published for the COMFAST CF-N1-S network appliance. The issue is classified as an OS command-injection vulnerability and carries a reported CVSS score of 9.1. Public vulnerability intelligence indicates that remote exploitation is possible and that exploit information has become publicly available. Organizations using the affected appliance should therefore treat internet-exposed instances as particularly sensitive while checking vendor remediation guidance. 🔗 Source: CVE vulnerability data / TheHackerWire #COMFAST #CVE202675094 #NetworkSecurity #Vulnerability #CyberSecurity #IoTSecurity #PatchManagement

    Post summary

    A high‑severity OS command‑injection vulnerability (CVE-2026-75094) has been disclosed for the COMFAST CF‑N1‑S appliance, with public exploit information available but no report of active exploitation.

    0000036
    75 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-75094 Command Injection in COMFAST CF-N1-S CGI Interface via ssid Argument https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-75094

    Post summary

    A brief disclosure lists CVE-2026-75094 as a command injection vulnerability in COMFAST CF‑N1‑S’s CGI interface, with no PoC, exploit code, or patch information provided.

    00000124
    4.1K followersView on X

Explore more