Comfast records
22 published records for vendor comfast.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 8
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')12
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')7
- CWE-20 Improper Input Validation1
- CWE-287 Improper Authentication1
The weakness classes this vendor ships most often: where to look.
CWEAll records
22 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2024-44466No exploit | COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4.comfast · cf-xr11 firmware · CWE-77 | Critical9.8 | — | 10.7% | Sep 11, 2024 |
40Plan | CVE-2023-38865No exploit | COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0.comfast · cf-xr11 firmware · CWE-77 | Critical9.8 | — | 2.4% | Aug 15, 2023 |
40Plan | CVE-2023-38866No exploit | COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588.comfast · cf-xr11 firmware · CWE-77 | Critical9.8 | — | 2.4% | Aug 15, 2023 |
39Monitor | CVE-2023-38863No exploit | An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the ifname and mac parameters in the sub_410074 functiocomfast · cf-xr11 firmware · CWE-77 | Critical9.8 | — | 1.2% | Aug 15, 2023 |
39Monitor | CVE-2023-38862No exploit | An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the destination parameter of sub_431F64 function in bincomfast · cf-xr11 firmware · CWE-77 | Critical9.8 | — | 1.2% | Aug 15, 2023 |
39Monitor | CVE-2023-38864No exploit | An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protal_delete_picname parameter in the sub_41171C fcomfast · cf-xr11 firmware · CWE-77 | Critical9.8 | — | 1.2% | Aug 15, 2023 |
37Monitor | CVE-2022-45725No exploit | Improper Input Validation in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to execute arbitrary code on the comfast · cf-wr610n firmware · CWE-20 | High8.8 | — | 7.0% | Feb 13, 2023 |
36Monitor | CVE-2025-57293No exploit | A command injection vulnerability in COMFAST CF-XR11 (firmware V2.7.2) exists in the multi_pppoe API, processed by the sub_423930 function icomfast · cf-xr11 firmware · CWE-77 | High8.8 | — | 1.7% | Sep 18, 2025 |
30Monitor | CVE-2023-30310No exploit | An issue discovered in Comfast Comfast CF-616AC routers allows attackers to hijack TCP sessions which could lead to a denial of service. | High7.5 | — | 0.4% | May 28, 2024 |
21Monitor | CVE-2022-45724No exploit | Incorrect Access Control in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to perform any HTTP request to an comfast · cf-wr610n firmware · CWE-287 | Medium5.4 | — | 0.5% | Feb 13, 2023 |
16Monitor | CVE-2026-2537No exploit | Comfast CF-E4 HTTP POST Request mbox-config command injectioncomfast · cf-e4 firmware · CWE-74 | Low2.0 | — | 25.3% | Feb 16, 2026 |
12Monitor | CVE-2026-2535No exploit | Comfast CF-N1 V2 mbox-config sub_44AB9C command injectioncomfast · cf-n1 firmware · CWE-74 | Low2.1 | — | 14.0% | Feb 16, 2026 |
12Monitor | CVE-2026-2534No exploit | Comfast CF-N1 V2 mbox-config sub_44AC4C command injectioncomfast · cf-n1 firmware · CWE-74 | Low2.1 | — | 13.5% | Feb 16, 2026 |
11Monitor | CVE-2026-2823No exploit | Comfast CF-E7 webmggnt mbox-config sub_41ACCC command injectioncomfast · cf-e7 firmware · CWE-74 | Low2.1 | — | 11.5% | Feb 20, 2026 |
11Monitor | CVE-2026-2824No exploit | Comfast CF-E7 webmggnt mbox-config sub_441CF4 command injectioncomfast · cf-e7 firmware · CWE-74 | Low2.1 | — | 11.5% | Feb 20, 2026 |
11Monitor | CVE-2026-3798No exploit | Comfast CF-AC100 Request Path mbox-config sub_44AC14 command injectioncomfast · cf-ac100 firmware · CWE-74 | Low2.0 | — | 10.9% | Mar 9, 2026 |
10Monitor | CVE-2025-9586No exploit | Comfast CF-N1 webmgnt wireless_device_dissoc command injectioncomfast · cf-n1 firmware · CWE-74 | Low2.1 | — | 8.3% | Aug 28, 2025 |
10Monitor | CVE-2025-9584No exploit | Comfast CF-N1 webmgnt update_interface_png command injectioncomfast · cf-n1 firmware · CWE-74 | Low2.1 | — | 8.3% | Aug 28, 2025 |
10Monitor | CVE-2025-9582No exploit | Comfast CF-N1 webmgnt ntp_timezone command injectioncomfast · cf-n1 firmware · CWE-74 | Low2.1 | — | 5.3% | Aug 28, 2025 |
10Monitor | CVE-2025-9581No exploit | Comfast CF-N1 webmgnt multi_pppoe command injectioncomfast · cf-n1 firmware · CWE-74 | Low2.1 | — | 5.3% | Aug 28, 2025 |
10Monitor | CVE-2025-9585No exploit | Comfast CF-N1 webmgnt wifilith_delete_pic_file command injectioncomfast · cf-n1 firmware · CWE-74 | Low2.1 | — | 5.1% | Aug 28, 2025 |
10Monitor | CVE-2025-9583No exploit | Comfast CF-N1 webmgnt ping_config command injectioncomfast · cf-n1 firmware · CWE-74 | Low2.1 | — | 5.1% | Aug 28, 2025 |
- CVE-2024-4446642Plan
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4.
CriticalCVSS 9.8No exploitEPSS 11%comfast · cf-xr11 firmwareSep 11, 2024
- CVE-2023-3886540Plan
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0.
CriticalCVSS 9.8No exploitEPSS 2%comfast · cf-xr11 firmwareAug 15, 2023
- CVE-2023-3886640Plan
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588.
CriticalCVSS 9.8No exploitEPSS 2%comfast · cf-xr11 firmwareAug 15, 2023
- CVE-2023-3886339Monitor
An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the ifname and mac parameters in the sub_410074 functio
CriticalCVSS 9.8No exploitEPSS 1%comfast · cf-xr11 firmwareAug 15, 2023
- CVE-2023-3886239Monitor
An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the destination parameter of sub_431F64 function in bin
CriticalCVSS 9.8No exploitEPSS 1%comfast · cf-xr11 firmwareAug 15, 2023
- CVE-2023-3886439Monitor
An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protal_delete_picname parameter in the sub_41171C f
CriticalCVSS 9.8No exploitEPSS 1%comfast · cf-xr11 firmwareAug 15, 2023
- CVE-2022-4572537Monitor
Improper Input Validation in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to execute arbitrary code on the
HighCVSS 8.8No exploitEPSS 7%comfast · cf-wr610n firmwareFeb 13, 2023
- CVE-2025-5729336Monitor
A command injection vulnerability in COMFAST CF-XR11 (firmware V2.7.2) exists in the multi_pppoe API, processed by the sub_423930 function i
HighCVSS 8.8No exploitEPSS 2%comfast · cf-xr11 firmwareSep 18, 2025
- CVE-2023-3031030Monitor
An issue discovered in Comfast Comfast CF-616AC routers allows attackers to hijack TCP sessions which could lead to a denial of service.
HighCVSS 7.5No exploitEPSS 0%May 28, 2024
- CVE-2022-4572421Monitor
Incorrect Access Control in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to perform any HTTP request to an
MediumCVSS 5.4No exploitEPSS 1%comfast · cf-wr610n firmwareFeb 13, 2023
- CVE-2026-253716Monitor
Comfast CF-E4 HTTP POST Request mbox-config command injection
LowCVSS 2.0No exploitEPSS 25%comfast · cf-e4 firmwareFeb 16, 2026
- CVE-2026-253512Monitor
Comfast CF-N1 V2 mbox-config sub_44AB9C command injection
LowCVSS 2.1No exploitEPSS 14%comfast · cf-n1 firmwareFeb 16, 2026
- CVE-2026-253412Monitor
Comfast CF-N1 V2 mbox-config sub_44AC4C command injection
LowCVSS 2.1No exploitEPSS 14%comfast · cf-n1 firmwareFeb 16, 2026
- CVE-2026-282311Monitor
Comfast CF-E7 webmggnt mbox-config sub_41ACCC command injection
LowCVSS 2.1No exploitEPSS 11%comfast · cf-e7 firmwareFeb 20, 2026
- CVE-2026-282411Monitor
Comfast CF-E7 webmggnt mbox-config sub_441CF4 command injection
LowCVSS 2.1No exploitEPSS 11%comfast · cf-e7 firmwareFeb 20, 2026
- CVE-2026-379811Monitor
Comfast CF-AC100 Request Path mbox-config sub_44AC14 command injection
LowCVSS 2.0No exploitEPSS 11%comfast · cf-ac100 firmwareMar 9, 2026
- CVE-2025-958610Monitor
Comfast CF-N1 webmgnt wireless_device_dissoc command injection
LowCVSS 2.1No exploitEPSS 8%comfast · cf-n1 firmwareAug 28, 2025
- CVE-2025-958410Monitor
Comfast CF-N1 webmgnt update_interface_png command injection
LowCVSS 2.1No exploitEPSS 8%comfast · cf-n1 firmwareAug 28, 2025
- CVE-2025-958210Monitor
Comfast CF-N1 webmgnt ntp_timezone command injection
LowCVSS 2.1No exploitEPSS 5%comfast · cf-n1 firmwareAug 28, 2025
- CVE-2025-958110Monitor
Comfast CF-N1 webmgnt multi_pppoe command injection
LowCVSS 2.1No exploitEPSS 5%comfast · cf-n1 firmwareAug 28, 2025
- CVE-2025-958510Monitor
Comfast CF-N1 webmgnt wifilith_delete_pic_file command injection
LowCVSS 2.1No exploitEPSS 5%comfast · cf-n1 firmwareAug 28, 2025
- CVE-2025-958310Monitor
Comfast CF-N1 webmgnt ping_config command injection
LowCVSS 2.1No exploitEPSS 5%comfast · cf-n1 firmwareAug 28, 2025