Comfast CF-WR631AX V3 Router OS Command Injection (CVE-2026-15511)
First seen Jul 14, 2026 · Updated Jul 14, 2026 · CVSS 9.8
A critical unauthenticated OS command injection vulnerability affects the Comfast CF-WR631AX V3 router firmware up to version 2.7.0.8, exploitable remotely via the system_wl_upload_pic_file function in the webmgnt FastCGI backend. A public exploit exists, and the vendor has not responded to disclosure, leaving affected devices permanently exposed to compromise.
Technical Analysis
The vulnerability resides in the system_wl_upload_pic_file function of /usr/bin/webmgnt, part of the router's FastCGI-based web management backend. Insufficient sanitization of the filename parameter allows an attacker to inject arbitrary OS commands, which are executed with the privileges of the web management process—typically root on embedded Linux router firmware. Exploitation requires no authentication and can be performed remotely over the network, making this a highly attractive target for botnet operators and IoT worm campaigns. Given the CVSS score of 9.8 and public exploit availability, mass scanning and automated exploitation attempts should be expected shortly after disclosure. Organizations that deploy edge/branch AI agent infrastructure or RAG pipeline components behind consumer/SOHO-grade routers like the CF-WR631AX face risk of network-level compromise, credential interception, or pivoting into internal agent hosts if these devices sit on the same network segment.
Affected Systems
Comfast CF-WR631AX V3 wireless router, firmware versions up to and including 2.7.0.8; specifically the webmgnt FastCGI backend binary at /usr/bin/webmgnt.
Indicators of Compromise
- File path: /usr/bin/webmgnt
- Vulnerable function: system_wl_upload_pic_file
- Exploit vector: crafted 'filename' parameter in FastCGI upload request
- Note: No specific hashes, IPs, or domains published at time of disclosure
Remediation Steps
- 1
Isolate or Retire Affected Devices
Immediately isolate CF-WR631AX V3 routers running firmware <= 2.7.0.8 from untrusted networks, or replace with vendor-supported hardware given the lack of vendor response.
- 2
Disable Remote Web Management
Turn off remote/WAN access to the web management interface and restrict administrative access to trusted LAN segments only.
- 3
Network Segmentation
Place IoT and SOHO networking devices on a segmented VLAN separate from servers, workstations, and any AI agent or RAG pipeline infrastructure to limit lateral movement.
- 4
Monitor for Exploitation
Deploy IDS/IPS signatures for anomalous FastCGI upload requests targeting webmgnt, and monitor for unexpected outbound connections or command execution on affected devices.
- 5
Vendor Escalation
Continue tracking vendor advisories; since Comfast has not responded, consider coordinated disclosure through CERT/CC or regional CERTs to pressure a patch release.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.