CVE-2026-78050Disclosure

LOWCVSS 8.6 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component Web Management. The manipulation of the argument timestr/ntp_client_enabled results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-22); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-08-22: 2Mentions · 2026-08-23: 2PoC Mentioned / Linked · 2026-08-23: 1Patch / Workaround · 2026-08-23: 1Technical Details · 2026-08-23: 208-2208-23
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-222
Disclosure1General1
2026-08-232
Disclosure2
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-78050 A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone… https://www.cve.org/CVERecord?id=CVE-2026-78050

    Post summary

    A new CVE (CVE‑2026‑78050) affecting Comfast CF‑N1‑S router 2.6.0.1 has been identified, noting the vulnerable function, but offering limited technical detail.

    00001956
    58.0K followersView on X
  • ADK Cyber@ADKCyber
    Disclosure

    CVSS 9.9 CVE-2026-78050 affects Comfast CF-N1-S 2.6.0.1 web management. Review if this device is deployed. https://nvd.nist.gov/vuln/detail/CVE-2026-78050 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/VrZ5iYYWp8

    Post summary

    The tweet announces a high‑severity CVE (CVE‑2026‑78050) affecting Comfast CF‑N1‑S devices, providing CVSS score and a NVD link without mentioning PoC, exploit code, active exploitation, or patches.

    0000025
    93 followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    🚨📡 **CRITICAL COMFAST ROUTER FLAW DISCLOSED — CVSS 9.9 AND PUBLIC EXPLOIT AVAILABLE** **CyberSignal Daily ✓ · 🌐 Network Security · August 23, 2026** 🎯 A critical vulnerability has been disclosed in the **Comfast CF-N1-S** wireless networking device. 🔥 **CVE-2026-78050** 📊 **CVSS: 9.9 / Critical** 📡 Affected: **CF-N1-S 2.6.0.1** 🌐 Attack vector: Remote 💥 Weakness: Stack-based buffer overflow The flaw exists in the device’s web-management functionality when processing time/NTP configuration data. Under attack: 🌐 crafted network input ↓ ⚙️ vulnerable management component processes it ↓ 💥 stack memory corruption ↓ ☠️ potential code execution or device crash. More importantly: ⚠️ **public exploit information is already available.** That significantly reduces the time defenders have before scanning or real-world abuse may begin. At the time of publication: ❌ no confirmed mass exploitation ❌ no patch details were publicly documented in the advisory reviewed. 🛡️ Organizations using this model should immediately: 🔎 identify exposed devices 🚫 remove management interfaces from the public internet 🔐 restrict management access to trusted networks 📊 monitor unusual configuration requests ⬆️ watch for vendor firmware updates. 🧠 **Why it matters:** edge devices are attractive targets because compromising the network infrastructure itself can provide attackers a foothold before endpoint security ever sees them. 🔗 Sources: NVD/CVE • VulDB • TheHackerWire #CyberSecurity #Comfast #CVE202678050 #CVSS99 #NetworkSecurity #RouterSecurity #Vulnerability #CyberNews

    Post summary

    The post announces the discovery of a critical buffer overflow in Comfast CF‑N1‑S routers, details the vulnerability, notes that a public exploit is available, and advises remediation steps despite no confirmed exploitation yet.

    0000082
    119 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-78050 A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone… https://www.cve.org/CVERecord?id=CVE-2026-78050 ----- Traducción: CVE-2026-78050 Se … http://infoflow.cloud`

    Post summary

    The snippet merely announces the existence of CVE-2026-78050 and points to its CVE record, providing no actionable details or indicators of exploitation.

    0000032
    102 followersView on X

Explore more