Comfast manufactures a focused line of wireless networking devices, primarily compact routers and access points such as the CF-N1 and CF-XR11 models, that serve small-business and consumer markets where management interfaces and firmware update mechanisms represent critical security boundaries. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and concentrate in input-handling and authentication weaknesses—command injection, code injection, improper input validation, and authentication bypass—that are endemic to embedded web interfaces and firmware processing pipelines. The exposure recurs across the vendor's small product portfolio, suggesting shared firmware codebases or architectural patterns that propagate risk across device lines. Defenders should prioritize inventory and segmentation of these devices, particularly internet-exposed management interfaces, and treat vendor security advisories as high-priority despite the narrow product scope. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Comfast over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-2823HIGH A vulnerability was detected in Comfast CF-E7 2.6.0.9. The impacted element is the function sub_41ACCC of the file /cgi-bin/mbox-config?method=SET§ion=ntp_timezone of the compo | Feb 20, 2026 | 8.8 | 36 | NO | NO |
CVE-2025-9582CRITICAL A flaw has been found in Comfast CF-N1 2.6.0. Affected is the function ntp_timezone of the file /usr/bin/webmgnt. Executing manipulation of the argument timestr can lead to command | Aug 28, 2025 | 9.8 | 36 | NO | NO |
CVE-2025-9581CRITICAL A vulnerability was detected in Comfast CF-N1 2.6.0. This impacts the function multi_pppoe of the file /usr/bin/webmgnt. Performing manipulation of the argument phy_interface resul | Aug 28, 2025 | 9.8 | 36 | NO | NO |
CVE-2026-2824HIGH A flaw has been found in Comfast CF-E7 2.6.0.9. This affects the function sub_441CF4 of the file /cgi-bin/mbox-config?method=SET§ion=ping_config of the component webmggnt. Exec | Feb 20, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-2537HIGH A vulnerability was identified in Comfast CF-E4 2.6.0.1. This impacts an unknown function of the file /cgi-bin/mbox-config?method=SET§ion=ntp_timezone of the component HTTP POS | Feb 16, 2026 | 7.2 | 35 | NO | NO |
CVE-2026-2535HIGH A vulnerability was found in Comfast CF-N1 V2 2.6.0.2. The impacted element is the function sub_44AB9C of the file /cgi-bin/mbox-config?method=SET§ion=ptest_channel. The manipu | Feb 16, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-2534HIGH A vulnerability has been found in Comfast CF-N1 V2 2.6.0.2. The affected element is the function sub_44AC4C of the file /cgi-bin/mbox-config?method=SET§ion=ptest_bandwidth. The | Feb 16, 2026 | 8.8 | 35 | NO | NO |
CVE-2022-45725HIGH Improper Input Validation in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to execute arbitrary code on the target via an HTTP POST request | Feb 13, 2023 | 8.8 | 33 | NO | NO |
CVE-2026-3798HIGH A vulnerability was detected in Comfast CF-AC100 2.6.0.8. This affects the function sub_44AC14 of the file /cgi-bin/mbox-config?method=SET§ion=ping_config of the component Requ | Mar 9, 2026 | 7.2 | 32 | NO | NO |
CVE-2025-9586HIGH A vulnerability was identified in Comfast CF-N1 2.6.0. This vulnerability affects the function wireless_device_dissoc of the file /usr/bin/webmgnt. Such manipulation of the argumen | Aug 28, 2025 | 8.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Comfast.
Media articles that mention a CVE ID that affects a product developed by Comfast — matched by CVE ID, not by vendor name.