CVE-2024-53946 Information

Description

The KuWFi 4G LTE AC900 router 1.0.13 is vulnerable to Cross-Site Request Forgery (CSRF) on its web management interface. This vulnerability allows an attacker to trick an authenticated admin user into performing unauthorized actions such as exploiting a command injection vulnerability in /goform/formMultiApnSetting. Successful exploitation can also lead to unauthorized configuration changes.

Reference

https://github.com/actuator/cve/blob/main/Kuwfi/CVE-2024-53946.txt https://github.com/actuator/cve/tree/main/Kuwfi https://kuwfi.com/products/kuwfi-gigabit-wireless-router-4g-lte-wifi-router-dual-band-portable-wifi-modem-hotspot-64-user-with-gigabit-wan-lan-rj11-port

CNNVD-202508-1639 (Published: 2025-08-14)

Share on: