CVE-2023-38864: Comfast Cf-XR11 Firmware
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
An issue in COMFAST CF-XR11 v.2.7.2 allows an attacker to execute arbitrary code via the protal_delete_picname parameter in the sub_41171C function at bin/webmgnt.
Affected products
- Comfast Cf-XR11 Firmware: version 2.7.2 only
Published 2023-08-15. Last modified 2026-06-17.