Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Comfast Project

First CVE: Jan 31, 2023Active for: 3 yearsTotal CVEs: 26

Comfast Project is a vendor of consumer-grade wireless networking appliances, with disclosed vulnerabilities concentrating in its CF-WR623N router and associated firmware. The recurring weakness classes center on web-application and access-control issues, including cross-site scripting, forced browsing, improper access control, and weak password-recovery mechanisms, which are typical of embedded device interfaces with limited security review. Live severity, exploitation, and product counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 83% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
8.7
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Comfast Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 31, 2023
3 years ago
Most Recent CVE
Mar 9, 2026
137 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-2823HIGH
A vulnerability was detected in Comfast CF-E7 2.6.0.9. The impacted element is the function sub_41ACCC of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the compo
Feb 20, 20268.836NONO
CVE-2025-9582CRITICAL
A flaw has been found in Comfast CF-N1 2.6.0. Affected is the function ntp_timezone of the file /usr/bin/webmgnt. Executing manipulation of the argument timestr can lead to command
Aug 28, 20259.836NONO
CVE-2025-9581CRITICAL
A vulnerability was detected in Comfast CF-N1 2.6.0. This impacts the function multi_pppoe of the file /usr/bin/webmgnt. Performing manipulation of the argument phy_interface resul
Aug 28, 20259.836NONO
CVE-2026-2824HIGH
A flaw has been found in Comfast CF-E7 2.6.0.9. This affects the function sub_441CF4 of the file /cgi-bin/mbox-config?method=SET&section=ping_config of the component webmggnt. Exec
Feb 20, 20268.835NONO
CVE-2026-2537HIGH
A vulnerability was identified in Comfast CF-E4 2.6.0.1. This impacts an unknown function of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone of the component HTTP POS
Feb 16, 20267.235NONO
CVE-2026-2535HIGH
A vulnerability was found in Comfast CF-N1 V2 2.6.0.2. The impacted element is the function sub_44AB9C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel. The manipu
Feb 16, 20268.835NONO
CVE-2026-2534HIGH
A vulnerability has been found in Comfast CF-N1 V2 2.6.0.2. The affected element is the function sub_44AC4C of the file /cgi-bin/mbox-config?method=SET&section=ptest_bandwidth. The
Feb 16, 20268.835NONO
CVE-2022-45725HIGH
Improper Input Validation in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to execute arbitrary code on the target via an HTTP POST request
Feb 13, 20238.833NONO
CVE-2026-3798HIGH
A vulnerability was detected in Comfast CF-AC100 2.6.0.8. This affects the function sub_44AC14 of the file /cgi-bin/mbox-config?method=SET&section=ping_config of the component Requ
Mar 9, 20267.232NONO
CVE-2025-9586HIGH
A vulnerability was identified in Comfast CF-N1 2.6.0. This vulnerability affects the function wireless_device_dissoc of the file /usr/bin/webmgnt. Such manipulation of the argumen
Aug 28, 20258.830NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
12%
50%
38%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network25 (96.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (3.8%)
Attack Complexity
Low26 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None22 (84.6%)
Unknown0 (0.0%)
Required4 (15.4%)
Privileges Required
Low8 (30.8%)
High2 (7.7%)
None16 (61.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Comfast Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Comfast Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Comfast Project's Products

View all 2 CNAs →

Top CWEs