Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Luminarydawn

#24992of 56,331
10Total CVSS
Vulnerabilities · 1
PT-2026-57563
10
2026-07-12
Comfast · Cf-Wr631Ax V3 · CVE-2026-15511
**Name of the Vulnerable Software and Affected Versions** Comfast CF-WR631AX V3 versions prior to 2.7.0.8 **Description** An OS command injection flaw exists in the FastCGI Backend component within the `/usr/bin/webmgnt` file. The issue occurs in the `system wl upload pic file()` function when processing the `filename` argument, allowing a remote attacker to execute arbitrary operating system commands. **Recommendations** Update Comfast CF-WR631AX V3 to a version newer than 2.7.0.8. As a temporary mitigation, restrict access to the `system wl upload pic file()` function within the FastCGI Backend component.