CVE-2026-15511: Critical OS Command Injection in Comfast CF-WR631AX Router
ID: f2264d57-0c1c-5c39-98eb-97c3417d2e9a
STIX ID: report--f2264d57-0c1c-5c39-98eb-97c3417d2e9a
Feed Name: CosmicBytez Labs
**CVE-2026-15511** is a critical (CVSS 9.8) unauthenticated OS command injection in the Comfast CF-WR631AX V3 web management FastCGI (`/usr/bin/webmgnt` -> `system_wl_upload_pic_file`) that allows remote attackers to execute arbitrary OS commands via the `filename` parameter; affected firmware up to 2.7.0.8, disclosed 2026-07-12 with no vendor patch at publication. Immediate mitigations include disabling remote admin, blocking admin access from untrusted networks, network segmentation, monitoring for suspicious outbound connections or HTTP POSTs to `/system_wl_upload_pic_file`, and replacing vulnerable devices if feasible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
