The KuWFi 4G AC900 LTE router 1.0.13 is vulnerable to command injection on the HTTP API endpoints /goform/formMultiApnSetting and /goform/atCmd. An authenticated attacker can execute arbitrary OS commands with root privileges via shell metacharacters in parameters such as pincode and cmds. Exploitation can lead to full system compromise, including enabling remote access (e.g., enabling telnet).
History

Thu, 14 Aug 2025 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Thu, 14 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77
CWE-94
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 14 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Description The KuWFi 4G AC900 LTE router 1.0.13 is vulnerable to command injection on the HTTP API endpoints /goform/formMultiApnSetting and /goform/atCmd. An authenticated attacker can execute arbitrary OS commands with root privileges via shell metacharacters in parameters such as pincode and cmds. Exploitation can lead to full system compromise, including enabling remote access (e.g., enabling telnet).
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-08-14T00:00:00.000Z

Updated: 2025-08-14T18:50:24.073Z

Reserved: 2024-11-25T00:00:00.000Z

Link: CVE-2024-53945

cve-icon Vulnrichment

Updated: 2025-08-14T15:10:26.927Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-14T14:15:30.237

Modified: 2025-08-15T13:13:07.817

Link: CVE-2024-53945

cve-icon Redhat

No data.