CVE-2025-57293 is a critical command injection vulnerability affecting COMFAST CF-XR11 firmware V2.7.2. An unsanitized parameter in the multi_pppoe API allows unauthenticated attackers to inject arbitrary commands via a POST request to the /cgi-bin/mbox-config endpoint. This vulnerability carries a high CVSS score of 8.8, indicating a severe risk of unauthorized access, arbitrary code execution, and full device compromise. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the high FAUCET Risk Score of 83/100 underscores its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.7.2CPE matchmatch criteria | cpe:2.3:o:comfast:cf-xr11_firmware:2.7.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.