logo

CVE-2026-15511: Critical OS Command Injection in Comfast CF-WR631AX Router

ID: f2264d57-0c1c-5c39-98eb-97c3417d2e9a

STIX ID: report--f2264d57-0c1c-5c39-98eb-97c3417d2e9a

Feed Name: CosmicBytez Labs

Threat Score
80/100

Date Published: 2026-07-13

Date Updated: 2026-07-15

...
...

**CVE-2026-15511** is a critical (CVSS 9.8) unauthenticated OS command injection in the Comfast CF-WR631AX V3 web management FastCGI (`/usr/bin/webmgnt` -> `system_wl_upload_pic_file`) that allows remote attackers to execute arbitrary OS commands via the `filename` parameter; affected firmware up to 2.7.0.8, disclosed 2026-07-12 with no vendor patch at publication. Immediate mitigations include disabling remote admin, blocking admin access from untrusted networks, network segmentation, monitoring for suspicious outbound connections or HTTP POSTs to `/system_wl_upload_pic_file`, and replacing vulnerable devices if feasible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.