Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54880 | The KuWFi 4G LTE AC900 router 1.0.13 is vulnerable to Cross-Site Request Forgery (CSRF) on its web management interface. This vulnerability allows an attacker to trick an authenticated admin user into performing unauthorized actions, such as exploiting a command injection vulnerability in /goform/formMultiApnSetting. Successful exploitation can also lead to unauthorized configuration changes. |
Sat, 16 Aug 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kuwfi
Kuwfi ac900 Router |
|
| Vendors & Products |
Kuwfi
Kuwfi ac900 Router |
Thu, 14 Aug 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-352 | |
| Metrics |
cvssV3_1
|
Thu, 14 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The KuWFi 4G LTE AC900 router 1.0.13 is vulnerable to Cross-Site Request Forgery (CSRF) on its web management interface. This vulnerability allows an attacker to trick an authenticated admin user into performing unauthorized actions, such as exploiting a command injection vulnerability in /goform/formMultiApnSetting. Successful exploitation can also lead to unauthorized configuration changes. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-08-14T15:50:12.058Z
Reserved: 2024-11-25T00:00:00.000Z
Link: CVE-2024-53946
Updated: 2025-08-14T15:48:59.047Z
Status : Deferred
Published: 2025-08-14T14:15:30.423
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-53946
No data.
OpenCVE Enrichment
Updated: 2025-08-16T21:41:16Z
EUVD