The KuWFi 4G AC900 LTE router 1.0.13 is vulnerable to command injection on the HTTP API endpoints /goform/formMultiApnSetting and /goform/atCmd. An authenticated attacker can execute arbitrary OS commands with root privileges via shell metacharacters in parameters such as pincode and cmds. Exploitation can lead to full system compromise, including enabling remote access (e.g., enabling telnet).
Metrics
Affected Vendors & Products
References
History
Sat, 16 Aug 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Kuwfi
Kuwfi ac900 Router |
|
Vendors & Products |
Kuwfi
Kuwfi ac900 Router |
Thu, 14 Aug 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-94 |
Thu, 14 Aug 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-77 CWE-94 |
|
Metrics |
cvssV3_1
|
Thu, 14 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The KuWFi 4G AC900 LTE router 1.0.13 is vulnerable to command injection on the HTTP API endpoints /goform/formMultiApnSetting and /goform/atCmd. An authenticated attacker can execute arbitrary OS commands with root privileges via shell metacharacters in parameters such as pincode and cmds. Exploitation can lead to full system compromise, including enabling remote access (e.g., enabling telnet). | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-08-14T00:00:00.000Z
Updated: 2025-08-14T18:50:24.073Z
Reserved: 2024-11-25T00:00:00.000Z
Link: CVE-2024-53945

Updated: 2025-08-14T15:10:26.927Z

Status : Awaiting Analysis
Published: 2025-08-14T14:15:30.237
Modified: 2025-08-15T13:13:07.817
Link: CVE-2024-53945

No data.