Comfast Cf-Ac100 vulnerabilities
4 known vulnerabilities affecting comfast/cf-ac100.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2026-3798P2HIGHCVSS 7.2v2.6.0.82026-03-09
CVE-2026-3798 [HIGH] CWE-74 CVE-2026-3798: A vulnerability was detected in Comfast CF-AC100 2.6.0.8. This affects the function sub_44AC14 of th
A vulnerability was detected in Comfast CF-AC100 2.6.0.8. This affects the function sub_44AC14 of the file /cgi-bin/mbox-config?method=SET§ion=ping_config of the component Request Path Handler. The manipulation results in command injection. The attack may be launched remotely. The exploit is now public and may be used. The vendor was contacted early abou
nvd
CVE-2026-4466P3MEDIUMCVSS 4.7v2.6.0.82026-03-20
CVE-2026-4466 [MEDIUM] CWE-74 CVE-2026-4466: A vulnerability has been found in Comfast CF-AC100 2.6.0.8. This affects an unknown function of the
A vulnerability has been found in Comfast CF-AC100 2.6.0.8. This affects an unknown function of the file /cgi-bin/mbox-config?method=SET§ion=ntp_timezone. The manipulation leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disc
nvd
CVE-2026-4468P3MEDIUMCVSS 4.7v2.6.0.82026-03-20
CVE-2026-4468 [MEDIUM] CWE-74 CVE-2026-4468: A vulnerability was determined in Comfast CF-AC100 2.6.0.8. Affected is an unknown function of the f
A vulnerability was determined in Comfast CF-AC100 2.6.0.8. Affected is an unknown function of the file /cgi-bin/mbox-config?method=SET§ion=update_interface_png. This manipulation causes command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about
nvd
CVE-2026-4467P3MEDIUMCVSS 4.7v2.6.0.82026-03-20
CVE-2026-4467 [MEDIUM] CWE-74 CVE-2026-4467: A vulnerability was found in Comfast CF-AC100 2.6.0.8. This impacts an unknown function of the file
A vulnerability was found in Comfast CF-AC100 2.6.0.8. This impacts an unknown function of the file /cgi-bin/mbox-config?method=SET§ion=wireless_device_dissoc. The manipulation results in command injection. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but di
nvd