CVE-2026-3798 details a command injection vulnerability in Comfast CF-AC100 2.6.0.8 firmware, specifically affecting the request path handler for ping configuration. This vulnerability carries a CVSS score of 7.2 HIGH, indicating that a remote attacker with high privileges can exploit it with low complexity to achieve high impacts on confidentiality, integrity, and availability. While not listed on CISA's KEV or Hot List, public exploit code is available, increasing the immediate risk of exploitation despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6.0.8CPE matchmatch criteria | cpe:2.3:o:comfast:cf-ac100_firmware:2.6.0.8:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
VER0 Comfast CF-AC100 Command Injection (CVE-2026-3798)
Mar 17, 2026VER0 Comfast CF-AC100 Command Injection (CVE-2026-3798)
Mar 17, 2026VER0 Comfast CF-AC100 Command Injection (CVE-2026-3798)
Mar 17, 2026