Skip to content
Noroxi

Comfast records

22 published records for vendor comfast.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
8
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

22 records
  • COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4.

    CriticalCVSS 9.8No exploitEPSS 11%

    comfast · cf-xr11 firmwareSep 11, 2024

  • COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0.

    CriticalCVSS 9.8No exploitEPSS 2%

    comfast · cf-xr11 firmwareAug 15, 2023

  • COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588.

    CriticalCVSS 9.8No exploitEPSS 2%

    comfast · cf-xr11 firmwareAug 15, 2023

  • An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the ifname and mac parameters in the sub_410074 functio

    CriticalCVSS 9.8No exploitEPSS 1%

    comfast · cf-xr11 firmwareAug 15, 2023

  • An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the destination parameter of sub_431F64 function in bin

    CriticalCVSS 9.8No exploitEPSS 1%

    comfast · cf-xr11 firmwareAug 15, 2023

  • An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protal_delete_picname parameter in the sub_41171C f

    CriticalCVSS 9.8No exploitEPSS 1%

    comfast · cf-xr11 firmwareAug 15, 2023

  • Improper Input Validation in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to execute arbitrary code on the

    HighCVSS 8.8No exploitEPSS 7%

    comfast · cf-wr610n firmwareFeb 13, 2023

  • A command injection vulnerability in COMFAST CF-XR11 (firmware V2.7.2) exists in the multi_pppoe API, processed by the sub_423930 function i

    HighCVSS 8.8No exploitEPSS 2%

    comfast · cf-xr11 firmwareSep 18, 2025

  • An issue discovered in Comfast Comfast CF-616AC routers allows attackers to hijack TCP sessions which could lead to a denial of service.

    HighCVSS 7.5No exploitEPSS 0%

    May 28, 2024

  • Incorrect Access Control in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to perform any HTTP request to an

    MediumCVSS 5.4No exploitEPSS 1%

    comfast · cf-wr610n firmwareFeb 13, 2023

  • CVE-2026-2537
    16Monitor

    Comfast CF-E4 HTTP POST Request mbox-config command injection

    LowCVSS 2.0No exploitEPSS 25%

    comfast · cf-e4 firmwareFeb 16, 2026

  • CVE-2026-2535
    12Monitor

    Comfast CF-N1 V2 mbox-config sub_44AB9C command injection

    LowCVSS 2.1No exploitEPSS 14%

    comfast · cf-n1 firmwareFeb 16, 2026

  • CVE-2026-2534
    12Monitor

    Comfast CF-N1 V2 mbox-config sub_44AC4C command injection

    LowCVSS 2.1No exploitEPSS 14%

    comfast · cf-n1 firmwareFeb 16, 2026

  • CVE-2026-2823
    11Monitor

    Comfast CF-E7 webmggnt mbox-config sub_41ACCC command injection

    LowCVSS 2.1No exploitEPSS 11%

    comfast · cf-e7 firmwareFeb 20, 2026

  • CVE-2026-2824
    11Monitor

    Comfast CF-E7 webmggnt mbox-config sub_441CF4 command injection

    LowCVSS 2.1No exploitEPSS 11%

    comfast · cf-e7 firmwareFeb 20, 2026

  • CVE-2026-3798
    11Monitor

    Comfast CF-AC100 Request Path mbox-config sub_44AC14 command injection

    LowCVSS 2.0No exploitEPSS 11%

    comfast · cf-ac100 firmwareMar 9, 2026

  • CVE-2025-9586
    10Monitor

    Comfast CF-N1 webmgnt wireless_device_dissoc command injection

    LowCVSS 2.1No exploitEPSS 8%

    comfast · cf-n1 firmwareAug 28, 2025

  • CVE-2025-9584
    10Monitor

    Comfast CF-N1 webmgnt update_interface_png command injection

    LowCVSS 2.1No exploitEPSS 8%

    comfast · cf-n1 firmwareAug 28, 2025

  • CVE-2025-9582
    10Monitor

    Comfast CF-N1 webmgnt ntp_timezone command injection

    LowCVSS 2.1No exploitEPSS 5%

    comfast · cf-n1 firmwareAug 28, 2025

  • CVE-2025-9581
    10Monitor

    Comfast CF-N1 webmgnt multi_pppoe command injection

    LowCVSS 2.1No exploitEPSS 5%

    comfast · cf-n1 firmwareAug 28, 2025

  • CVE-2025-9585
    10Monitor

    Comfast CF-N1 webmgnt wifilith_delete_pic_file command injection

    LowCVSS 2.1No exploitEPSS 5%

    comfast · cf-n1 firmwareAug 28, 2025

  • CVE-2025-9583
    10Monitor

    Comfast CF-N1 webmgnt ping_config command injection

    LowCVSS 2.1No exploitEPSS 5%

    comfast · cf-n1 firmwareAug 28, 2025