PT-2025-33072 · Kuwfi · Kuwfi 5G01-X55

Published

2025-08-13

·

Updated

2025-08-14

·

CVE-2025-43988

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: KuWFi 5G01-X55 version FL2020 V0.0.12
Description: KuWFi 5G01-X55 devices expose an unauthenticated API endpoint (ajax get.cgi), allowing remote attackers to retrieve sensitive configuration data, including admin credentials.
Recommendations: Disable or restrict access to the ajax get.cgi API endpoint.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-43988

Affected Products

Kuwfi 5G01-X55