OS Command Injection in Comfast CF-WR631AX V3 Due to FastCGI Backend Flaw

⚠️ CVE-Referenzen: CVE-2026-15511
Comfast - Cf-wr631ax V3 - CRITICAL - CVE-2026-15511. An OS command injection vulnerability exists in the Comfast CF-WR631AX V3, specifically in the system_wl_upload_pic_file function within the FastCGI Backend component. This vulnerability arises due to improper handling of the filename argument in the webmgnt interface, allowing an attacker to execute arbitrary commands on the system. The vulnerability can be exploited remotely, posing significant security risks. The vendor has been alerted about the issue but has not provided a response. BADGES: 👾 EXPLOITED | 🟡 PoC | SecurityVulnerability.io
Quelle: securityvulnerability.io