CVE-2026-12814
Received Received - Intake
Command Injection in Comfast CF-WR631AX Router

Publication date: 2026-06-21

Last updated on: 2026-06-21

Assigner: VulDB

Description
A flaw has been found in Comfast CF-WR631AX V3 up to 2.7.0.8. This issue affects the function system of the file /cgi-bin/mbox-config?section=ping_config of the component API Endpoint. This manipulation of the argument destination causes os command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-21
Last Modified
2026-06-21
Generated
2026-06-22
AI Q&A
2026-06-22
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
comfast cf-wr631ax to 2.7.0.8 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CWE-77 The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a flaw found in the Comfast CF-WR631AX V3 device firmware up to version 2.7.0.8. It affects the system function in the API endpoint located at /cgi-bin/mbox-config?section=ping_config. Specifically, the vulnerability arises from improper handling of the 'destination' argument, which allows an attacker to perform OS command injection.

This means that an attacker can remotely send crafted input to this endpoint to execute arbitrary operating system commands on the device.

The exploit for this vulnerability has been published, making it possible for attackers to use it in real-world attacks. The vendor was informed but did not respond.

Impact Analysis

This vulnerability can have serious impacts because it allows remote attackers to execute arbitrary operating system commands on the affected device.

  • Unauthorized control over the device, potentially leading to device compromise.
  • Disruption of device functionality or network services.
  • Potential pivot point for further attacks within the network.
  • Exposure of sensitive information or data breaches if the device is used to handle such data.
Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12814. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart