CVE-2024-53946

8.8

KuWFi · 4G LTE AC900 Router

The KuWFi 4G LTE AC900 router version 1.0.13 is vulnerable to Cross-Site Request Forgery, allowing attackers to trick authenticated admins into executing unauthorized commands.

Executive summary

A Cross-Site Request Forgery vulnerability in the KuWFi 4G LTE AC900 router allows an attacker to execute unauthorized commands and modify configurations by targeting an authenticated administrator.

Vulnerability

This vulnerability is a Cross-Site Request Forgery (CSRF) flaw residing in the web management interface. It enables an attacker to perform unauthorized actions, including command injection via the /goform/formMultiApnSetting endpoint, by leveraging an authenticated admin user session.

Business impact

The exploitation of this flaw can lead to a complete compromise of the router, including unauthorized configuration changes and potential remote code execution. With a CVSS score of 8.8, the vulnerability poses a high risk to business operations, as it allows attackers to gain persistence, intercept traffic, or disrupt network services provided by the device.

Remediation

Immediate Action: Restrict access to the router web management interface to trusted internal networks only and avoid accessing untrusted websites while logged into the administrative portal.

Proactive Monitoring: Monitor device access logs for unusual administrative activity or unauthorized modifications to APN settings and system configurations.

Compensating Controls: Implement a strict firewall policy to block external access to the management interface and ensure the device is not exposed directly to the public internet.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the technical write-up referenced by the CVE record.

Analyst recommendation

Given the potential for command injection and complete device takeover, users are urged to audit their network perimeter security immediately. Since a patch status is currently unknown, administrators should prioritize isolating the management interface from all untrusted networks to prevent unauthorized CSRF-based exploitation.

More KuWFi CVEs

Sources