{"id":"CVE-2026-77004","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-77004","summary":"A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the file /cgi-bin/mbox-config?method=SET&section=ptest_sn. Executing a manipulation of the argument…","details":"A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the file /cgi-bin/mbox-config?method=SET&section=ptest_sn. Executing a manipulation of the argument sn can lead to command injection. The attack can be launched remotely. The exploit has been published and may be used.","published":"2026-08-20T16:18:31.580","modified":"2026-08-20T17:19:48.930","cvss":{"score":7.4,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/lxiansheng488-bit/-/blob/main/%E5%8E%82%E5%95%86comefast%20%20CF-N1-S%20V2.pdf"},{"type":"WEB","url":"https://vuldb.com/cve/CVE-2026-77004"},{"type":"WEB","url":"https://vuldb.com/submit/880584"},{"type":"WEB","url":"https://vuldb.com/vuln/393623"},{"type":"WEB","url":"https://vuldb.com/vuln/393623/cti"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-20T17:19:48.930"}}