CVE-2026-75363
An issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to execute arbitrary code via the /usr/bin/webmgnt, /cgi-bin/mbox-config, and the parameters timestr, display_n.
- Published Aug 26, 2026
- CVSS 6.8 medium
- 0.5% chance of exploitation in the next 30 days (EPSS)