CVE-2026-75363

An issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to execute arbitrary code via the /usr/bin/webmgnt, /cgi-bin/mbox-config, and the parameters timestr, display_n.

  • Published Aug 26, 2026
  • CVSS 6.8 medium
  • 0.5% chance of exploitation in the next 30 days (EPSS)

CVE-2026-75363 at the National Vulnerability Database