PT-2025-33278 · Kuwfi · Kuwfi 4G Ac900 Lte Router

Published

2025-08-14

·

Updated

2025-08-16

·

CVE-2024-53945

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: KuWFi 4G AC900 LTE router version 1.0.13
Description: The KuWFi 4G AC900 LTE router is susceptible to command injection via the HTTP API endpoints /goform/formMultiApnSetting and /goform/atCmd. An authenticated attacker can execute arbitrary OS commands with root privileges by injecting shell metacharacters into parameters like pincode and cmds. Successful exploitation can result in full system compromise, potentially including enabling remote access such as telnet.
Recommendations: KuWFi 4G AC900 LTE router version 1.0.13: As a temporary workaround, restrict access to the affected API endpoints /goform/formMultiApnSetting and /goform/atCmd to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-53945

Affected Products

Kuwfi 4G Ac900 Lte Router