The KuWFi 4G AC900 LTE router 1.0.13 is vulnerable to command injection on the HTTP API endpoints /goform/formMultiApnSetting and /goform/atCmd. An authenticated attacker can execute arbitrary OS commands with root privileges via shell metacharacters in parameters such as pincode and cmds. Exploitation can lead to full system compromise, including enabling remote access (e.g., enabling telnet).
                
            Metrics
Affected Vendors & Products
References
        History
                    Sat, 16 Aug 2025 21:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Kuwfi Kuwfi ac900 Router | |
| Vendors & Products | Kuwfi Kuwfi ac900 Router | 
Thu, 14 Aug 2025 19:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-94 | 
Thu, 14 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-77 CWE-94 | |
| Metrics | cvssV3_1 
 
 | 
Thu, 14 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | The KuWFi 4G AC900 LTE router 1.0.13 is vulnerable to command injection on the HTTP API endpoints /goform/formMultiApnSetting and /goform/atCmd. An authenticated attacker can execute arbitrary OS commands with root privileges via shell metacharacters in parameters such as pincode and cmds. Exploitation can lead to full system compromise, including enabling remote access (e.g., enabling telnet). | |
| References |  | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: mitre
Published: 2025-08-14T00:00:00.000Z
Updated: 2025-08-14T18:50:24.073Z
Reserved: 2024-11-25T00:00:00.000Z
Link: CVE-2024-53945
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-08-14T15:10:26.927Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-08-14T14:15:30.237
Modified: 2025-08-15T13:13:07.817
Link: CVE-2024-53945
 Redhat
                        Redhat
                    No data.