PT-2026-79742 · Comfast · Cf-N1-S

·

CVE-2026-78050

·

Published

2026-08-22

·

Updated

2026-08-24

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Comfast CF-N1-S version 2.6.0.1
Description A stack-based buffer overflow exists in the Web Management component. The issue occurs when the device processes input for NTP timezone settings via the /cgi-bin/mbox-config?method=SET&section=ntp timezone endpoint. Specifically, manipulating the timestr or ntp client enabled arguments can trigger the sub 41AD7C() function to overwrite critical memory. This flaw allows unauthenticated remote attackers to execute arbitrary code or cause a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. Restrict access to the /cgi-bin/mbox-config?method=SET&section=ntp timezone endpoint to minimize the risk of exploitation.

Exploit

Stack Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78050

Affected Products

Cf-N1-S