A critical stack-based buffer overflow, tracked as CVE-2026-94003 with a CVSS v3 score of 10.0, affects Comfast CF-N1-S wireless routers running firmware 2.6.0.1. The flaw resides in the get_css_path_from_uri function and is reachable through the Web Management Interface endpoint /cgi-bin/mbox-config, potentially allowing remote unauthenticated exploitation without user interaction. A public proof of concept is available.
No confirmed exploitation in the wild, fixed firmware release, or vendor-confirmed mitigation has been reported. Organizations should immediately restrict access to router management interfaces, disable remote administration where feasible, monitor for anomalous requests to /cgi-bin/mbox-config, and prepare to replace affected devices if Comfast does not issue remediation.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
A disclosure reported a critical stack-based buffer overflow (CVE-2026-94003) affecting Comfast CF-N1-S routers running firmware 2.6.0.1. The flaw is reachable through the Web Management Interface endpoint /cgi-bin/mbox-config, and a public proof-of-concept was reported as available.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.