Vulnerability record · CVE-2022-45725 · published 13 February 2023
CVE-2022-45725: Comfast cf-wr610n firmware improper input validation vulnerability
Comfast · Cf Wr610n Firmware
Improper Input Validation in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to execute arbitrary code on the target via an HTTP POST request
Description
Improper Input Validation in Comfast router CF-WR6110N V2.3.1 allows a remote attacker on the same network to execute arbitrary code on the target via an HTTP POST request
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://sn0ox.com/research/2023/02/05/CVE-COMFAST-CF-WR610N.html | ExploitThird Party Advisory |
| http://sn0ox.com/research/2023/02/05/CVE-COMFAST-CF-WR610N.html | ExploitThird Party Advisory |
| http://sn0ox.com/research/2023/02/05/CVE-COMFAST-CF-WR610N.html | ExploitThird Party Advisory |
Track CVE-2022-45725 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-45725), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.