CVE-2026-75363

Medium severity, CVSS 6.8. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to execute arbitrary code via the /usr/bin/webmgnt, /cgi-bin/mbox-config, and the parameters timestr, display_n.

Published 2026-08-26. Last modified 2026-08-31.