Cyber & AI intelligence
Wasteland.
Briefs indexed2769
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-94003 2026-09-20

CVE-2026-94003: Critical Unauthenticated Stack Overflow in Comfast CF-N1-S Routers

"A publicly disclosed stack-based buffer overflow in the Comfast CF-N1-S 2.6.0.1 web management interface is reported to allow unauthenticated remote attackers to fully compromise affected devices, based on a…"

A publicly disclosed stack-based buffer overflow in the Comfast CF-N1-S 2.6.0.1 web management interface is reported to allow unauthenticated remote attackers to fully compromise affected devices, based on a VulDB-assigned maximum 10.0 CVSS v3.1 score. The severity rating reflects the CNA's assessment of the flaw's potential impact rather than independently verified exploitation, and no vendor confirmation is available in the published record.

What Is It

CVE-2026-94003 is a stack-based buffer overflow (CWE-121, CWE-119) in the get_css_path_from_uri function of /cgi-bin/mbox-config, part of the Comfast CF-N1-S Web Management Interface. Manipulation of input handled by that function overflows a stack buffer. The attack can be initiated remotely, and the exploit has been disclosed to the public and may be used.

The record was published by VulDB ([email protected]) on 2026-09-20 and currently carries NVD status "Received."

Why It Matters

The CVSS v3.1 base score is 10.0 (CRITICAL) with vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, network-reachable, low complexity, no privileges, no user interaction, and a changed scope with high confidentiality, integrity, and availability impact. The CVSS v4.0 assessment scores 9.3 (CRITICAL) and rates exploit maturity as PROOF_OF_CONCEPT. The legacy CVSS v2 vector AV:N/AC:L/Au:N/C:C/I:C/A:C also scores 10.0 with complete impact across all three pillars.

As of this writing, CVE-2026-94003 does not appear in the CISA Known Exploited Vulnerabilities catalog (searchable at the link in Sources), so active in-the-wild exploitation is not confirmed. A public proof-of-concept nonetheless lowers the bar considerably for opportunistic attackers scanning for exposed device management interfaces.

What's Vulnerable

Patch Status

The NVD and VulDB records for CVE-2026-94003 list no vendor patch, fixed version, or mitigation guidance, and Comfast has published no advisory for the issue at the time of writing. Because the CVE is absent from the CISA KEV catalog, no federal remediation deadline applies. Operators of CF-N1-S 2.6.0.1 devices should treat the management interface as untrusted-network-exposed until vendor guidance is published.

Sources