Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-24812 | KuWFi CPF908-CP5 WEB5.0_LCD_20210125 devices have multiple unauthenticated access control vulnerabilities within goform/goform_set_cmd_process and goform/goform_get_cmd_process. These allow an unauthenticated attacker to retrieve sensitive information (including the device admin username and password), modify critical device settings, and send arbitrary SMS messages. |
Sat, 16 Aug 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kuwfi
Kuwfi cpf908-cp5 |
|
| Vendors & Products |
Kuwfi
Kuwfi cpf908-cp5 |
Fri, 15 Aug 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-306 | |
| Metrics |
cvssV3_1
|
Thu, 14 Aug 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | KuWFi CPF908-CP5 WEB5.0_LCD_20210125 devices have multiple unauthenticated access control vulnerabilities within goform/goform_set_cmd_process and goform/goform_get_cmd_process. These allow an unauthenticated attacker to retrieve sensitive information (including the device admin username and password), modify critical device settings, and send arbitrary SMS messages. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-08-15T12:58:59.330Z
Reserved: 2025-04-21T00:00:00.000Z
Link: CVE-2025-43983
Updated: 2025-08-15T12:44:57.361Z
Status : Deferred
Published: 2025-08-14T15:15:36.393
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-43983
No data.
OpenCVE Enrichment
Updated: 2025-08-16T21:41:13Z
EUVD