CVE-2026-2535 | Comfast CF-N1 V2 2.6.0.2 mbox-config?method=SET&section=ptest_channel sub_44AB9C command injection

SecurityVulns

A vulnerability classified as critical was found in Comfast CF-N1 V2 2.6.0.2. The impacted element is the function sub_44AB9C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel. The manipulation of the argument channel results in command injection.

This vulnerability is reported as CVE-2026-2535. The attack can be launched remotely. Moreover, an exploit is present.

The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More