Known Vulnerabilities for products from Comfast

Listed below are 19 of the newest known vulnerabilities associated with the vendor "Comfast".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-15511 json Not Provided 2026-07-12 2026-07-14
CVE-2026-12814 json Not Provided 2026-06-21 2026-06-22
CVE-2026-3798 json A vulnerability was detected in Comfast CF-AC100 2.6.0.8. This affects the function sub_44AC14 of the file /cgi-bin/mbox-conf... Not Provided 2026-03-09 2026-04-29
CVE-2026-2824 json A flaw has been found in Comfast CF-E7 2.6.0.9. This affects the function sub_441CF4 of the file /cgi-bin/mbox-config?method=... Not Provided 2026-02-20 2026-04-29
CVE-2026-2823 json A vulnerability was detected in Comfast CF-E7 2.6.0.9. The impacted element is the function sub_41ACCC of the file /cgi-bin/m... Not Provided 2026-02-20 2026-04-29
CVE-2026-2537 json A vulnerability was identified in Comfast CF-E4 2.6.0.1. This impacts an unknown function of the file /cgi-bin/mbox-config?me... Not Provided 2026-02-16 2026-04-29
CVE-2026-2535 json A vulnerability was found in Comfast CF-N1 V2 2.6.0.2. The impacted element is the function sub_44AB9C of the file /cgi-bin/m... Not Provided 2026-02-16 2026-04-29
CVE-2026-2534 json A vulnerability has been found in Comfast CF-N1 V2 2.6.0.2. The affected element is the function sub_44AC4C of the file /cgi-... Not Provided 2026-02-16 2026-04-29
CVE-2025-9586 json A vulnerability was identified in Comfast CF-N1 2.6.0. This vulnerability affects the function wireless_device_dissoc of the ... Not Provided 2025-08-28 2026-04-29
CVE-2025-9585 json A vulnerability was determined in Comfast CF-N1 2.6.0. This affects the function wifilith_delete_pic_file of the file /usr/bi... Not Provided 2025-08-28 2026-04-29
CVE-2025-9584 json A vulnerability was found in Comfast CF-N1 2.6.0. Affected by this issue is the function update_interface_png of the file /us... Not Provided 2025-08-28 2026-04-29
CVE-2025-9583 json A vulnerability has been found in Comfast CF-N1 2.6.0. Affected by this vulnerability is the function ping_config of the file... Not Provided 2025-08-28 2026-04-29
CVE-2025-9582 json A flaw has been found in Comfast CF-N1 2.6.0. Affected is the function ntp_timezone of the file /usr/bin/webmgnt. Executing m... Not Provided 2025-08-28 2026-04-29
CVE-2025-9581 json A vulnerability was detected in Comfast CF-N1 2.6.0. This impacts the function multi_pppoe of the file /usr/bin/webmgnt. Perf... Not Provided 2025-08-28 2026-04-29
CVE-2023-38866 json COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_415588. Attackers can send POST request... 9.8 - CRITICAL 2023-08-15 2023-08-22
CVE-2023-38865 json COMFAST CF-XR11 V2.7.2 has a command injection vulnerability detected at function sub_4143F0. Attackers can send POST request... 9.8 - CRITICAL 2023-08-15 2023-08-22
CVE-2023-38864 json An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protal_delete_picname parameter in t... 9.8 - CRITICAL 2023-08-15 2023-08-22
CVE-2023-38863 json An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the ifname and mac parameters in the sub... 9.8 - CRITICAL 2023-08-15 2023-08-22
CVE-2023-38862 json An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the destination parameter of sub_431F64 ... 9.8 - CRITICAL 2023-08-15 2023-08-22
CVE-2022-45725 json Improper Input Validation in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to execute arbitra... Not Provided 2023-02-13 2026-07-09

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report