An issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to execute arbitrary code via the /usr/bin/webmgnt, /cgi-bin/mbox-config, and the parameters timestr, display_n.Referenceshttps://github.com/Flechao1/iot-vuln/tree/main/cve-pocs/CVE-2026-75363