Comfast · Cf-N1-S · CVE-2026-76008
**Name of the Vulnerable Software and Affected Versions**
Comfast CF-N1-S version 2.6.0.1
**Description**
A remote attack is possible due to a stack-based buffer overflow in the URI Parameter Parsing component. The issue occurs within the `get para from uri()` function located in the `/cgi-bin/mbox-config` endpoint when the `width` or `height` arguments are manipulated.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the `/cgi-bin/mbox-config` endpoint to minimize the risk of exploitation.