A flaw has been found in Comfast CF-N1 2.6.0. Affected is...
Moderate severity
Unreviewed
Published
Aug 28, 2025
to the GitHub Advisory Database
•
Updated Sep 11, 2025
Description
Published by the National Vulnerability Database
Aug 28, 2025
Published to the GitHub Advisory Database
Aug 28, 2025
Last updated
Sep 11, 2025
A flaw has been found in Comfast CF-N1 2.6.0. Affected is the function ntp_timezone of the file /usr/bin/webmgnt. Executing manipulation of the argument timestr can lead to command injection. The attack may be launched remotely. The exploit has been published and may be used.
References