The KuWFi 4G AC900 LTE router 1.0.13 is vulnerable to command injection on the HTTP API endpoints /goform/formMultiApnSetting and /goform/atCmd. An authenticated attacker can execute arbitrary OS commands with root privileges via shell metacharacters in parameters such as pincode and cmds. Exploitation can lead to full system compromise, including enabling remote access (e.g., enabling telnet).
References
Configurations
No configuration.
History
14 Aug 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CWE |
14 Aug 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-77 CWE-94 |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
14 Aug 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-14 14:15
Updated : 2025-08-15 13:13
NVD link : CVE-2024-53945
Mitre link : CVE-2024-53945
CVE.ORG link : CVE-2024-53945
JSON object : View
Products Affected
No product.
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')