The KuWFi 4G AC900 LTE router 1.0.13 is vulnerable to command injection on the HTTP API endpoints /goform/formMultiApnSetting and /goform/atCmd. An authenticated attacker can execute arbitrary OS commands with root privileges via shell metacharacters in parameters such as pincode and cmds. Exploitation can lead to full system compromise, including enabling remote access (e.g., enabling telnet).
Metrics
Affected Vendors & Products
References
History
Thu, 14 Aug 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-94 |
Thu, 14 Aug 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-77 CWE-94 |
|
Metrics |
cvssV3_1
|
Thu, 14 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The KuWFi 4G AC900 LTE router 1.0.13 is vulnerable to command injection on the HTTP API endpoints /goform/formMultiApnSetting and /goform/atCmd. An authenticated attacker can execute arbitrary OS commands with root privileges via shell metacharacters in parameters such as pincode and cmds. Exploitation can lead to full system compromise, including enabling remote access (e.g., enabling telnet). | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-08-14T00:00:00.000Z
Updated: 2025-08-14T18:50:24.073Z
Reserved: 2024-11-25T00:00:00.000Z
Link: CVE-2024-53945

Updated: 2025-08-14T15:10:26.927Z

Status : Awaiting Analysis
Published: 2025-08-14T14:15:30.237
Modified: 2025-08-15T13:13:07.817
Link: CVE-2024-53945

No data.