CVE-2026-78050 — Comfast CF-N1-S Stack Overflow

CVE & Vulnerabilities · August 25, 2026

CVE & Vulnerabilities·nvd.nist.gov

A stack-based buffer overflow has been found in Comfast CF-N1-S wireless routers running firmware 2.6.0.1, located in the NTP timezone handler of the device's CGI-based web management interface. The timestr and ntp_client_enabled parameters aren't properly validated before being copied into memory, and the flaw can reportedly be triggered over the network without authentication. A working exploit is already circulating publicly, so unpatched devices are at immediate risk.

// source: nvd.nist.gov ↗

Back to Blog