PT-2025-53779 · Kuwfi+1 · Kuwfi 4G Lte Ac900+1

Actuator

·

Publicado

2025-12-29

·

Atualizado

2025-12-30

·

CVE-2025-68706

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GoAhead-Webs on KuWFi 4G LTE AC900 version 1.0.13
Description A stack-based buffer overflow exists in the GoAhead-Webs HTTP daemon. The /goform/formMultiApnSetting handler uses sprintf() to copy the pincode parameter, supplied by the user, into a fixed 132-byte stack buffer without proper bounds checking. This can lead to corruption of adjacent stack memory, potentially causing the web server to crash and, under specific circumstances, enabling arbitrary code execution. The vulnerable parameter is pincode.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Correção

Stack Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-68706

Produtos afetados

Goahead-Webs
Kuwfi 4G Lte Ac900