CVE-2024-53945

The KuWFi 4G AC900 LTE router 1.0.13 is vulnerable to command injection on the HTTP API endpoints /goform/formMultiApnSetting and /goform/atCmd. An authenticated attacker can execute arbitrary OS commands with root privileges via shell metacharacters in parameters such as pincode and cmds. Exploitation can lead to full system compromise, including enabling remote access (e.g., enabling telnet).
Configurations

No configuration.

History

No history.

Information

Published : 2025-08-14 14:15

Updated : 2025-08-15 13:13


NVD link : CVE-2024-53945

Mitre link : CVE-2024-53945

CVE.ORG link : CVE-2024-53945


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')