CVE-2025-9581 is a critical command injection vulnerability affecting Comfast CF-N1 2.6.0 firmware, specifically within the multi_pppoe function of the /usr/bin/webmgnt file. This flaw allows for remote, unauthenticated attackers to execute arbitrary commands by manipulating the phy_interface argument, leading to complete compromise of the device. With a CVSS score of 9.8 (CRITICAL) and public exploit code available, this vulnerability poses an immediate and severe risk, evidenced by its high community discussion and FAUCET Risk Score, despite not being in the KEV catalog or having widespread media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6.0CPE matchmatch criteria | cpe:2.3:o:comfast:cf-n1_firmware:2.6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.