Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-24818 | An issue was discovered on KuWFi GC111 devices (Hardware Version: CPE-LM321_V3.2, Software Version: GC111-GL-LM321_V3.0_20191211). They are vulnerable to unauthenticated /goform/goform_set_cmd_process requests. A crafted POST request, using the SSID parameter, allows remote attackers to execute arbitrary OS commands with root privileges. |
Sat, 16 Aug 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kuwfi
Kuwfi gc111 |
|
| Vendors & Products |
Kuwfi
Kuwfi gc111 |
Fri, 15 Aug 2025 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-78 | |
| Metrics |
cvssV3_1
|
Thu, 14 Aug 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered on KuWFi GC111 devices (Hardware Version: CPE-LM321_V3.2, Software Version: GC111-GL-LM321_V3.0_20191211). They are vulnerable to unauthenticated /goform/goform_set_cmd_process requests. A crafted POST request, using the SSID parameter, allows remote attackers to execute arbitrary OS commands with root privileges. | |
| References |
|
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-08-15T12:59:07.594Z
Reserved: 2025-04-21T00:00:00.000Z
Link: CVE-2025-43984
Updated: 2025-08-15T12:47:11.106Z
Status : Deferred
Published: 2025-08-14T14:15:31.210
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-43984
No data.
OpenCVE Enrichment
Updated: 2025-08-16T21:41:17Z
EUVD