ZeroHour

CVE-2024-53944

Unauthenticated command injection in Tuoshi/Dionlink LT15D and LT21B 4G Wi-Fi routers

CVSS 3.1
9.8 critical
EPSS
40%p99
Published
()
Modified
AI analysis

CVE-2024-53944 is an unauthenticated command injection flaw (CWE-94) in Tuoshi/Dionlink LT15D and LT21B 4G Wi-Fi router firmware. An attacker with network access to the device's web management interface sends shell metacharacters inside JSON parameters to the /goform/formJsonAjaxReq endpoint, which fails to sanitize the input before passing it to the operating system. Successful exploitation lets the attacker run arbitrary OS commands with root privileges, giving full control of the router (traffic interception, configuration changes, or pivoting to connected networks). All LT15D devices on firmware through M7628NNxlSPv2xUI_v1.0.1802.10.08_P4 and LT21B devices on firmware through M7628xUSAxUIv2_v1.0.1481.15.02_P0 are affected. The flaw is not yet in CISA's KEV and no public proof-of-concept or confirmed in-the-wild exploitation is known, but the high EPSS score (39.7%, 99th percentile) indicates an elevated probability of exploitation within 30 days.

What to do: Check devices for the affected firmware builds and, when the vendor releases one, upgrade to a firmware version newer than M7628NNxlSPv2xUI_v1.0.1802.10.08_P4 (LT15D) or M7628xUSAxUIv2_v1.0.1481.15.02_P0 (LT21B). Until then, disable or firewall WAN-side remote management so /goform/formJsonAjaxReq is reachable only from trusted LAN networks, and monitor devices for signs of unexpected commands or configuration changes.

Affected
Tuoshi (Dionlink) LT15D 4G Wi-Fi routerthrough M7628NNxlSPv2xUI_v1.0.1802.10.08_P4
Tuoshi (Dionlink) LT21B 4G Wi-Fi routerthrough M7628xUSAxUIv2_v1.0.1481.15.02_P0
Estimated exposure
unknown; no public install-base or internet-scan counts exist for these niche budget 4G CPE models — These are low-cost 4G CPE routers sold mainly through online marketplaces and regional channels with no published active-install or exposed-device scan data, so the affected population cannot be quantified; exposure depends heavily on how…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered on Tuoshi/Dionlink LT15D 4G Wi-Fi devices through M7628NNxlSPv2xUI_v1.0.1802.10.08_P4 and LT21B devices through M7628xUSAxUIv2_v1.0.1481.15.02_P0. A unauthenticated remote attacker with network access can exploit a command injection vulnerability. The /goform/formJsonAjaxReq endpoint fails to sanitize shell metacharacters sent via JSON parameters, thus allowing attackers to execute arbitrary OS commands with root privileges.

Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.