CVE-2024-53944
Unauthenticated command injection in Tuoshi/Dionlink LT15D and LT21B 4G Wi-Fi routers
CVE-2024-53944 is an unauthenticated command injection flaw (CWE-94) in Tuoshi/Dionlink LT15D and LT21B 4G Wi-Fi router firmware. An attacker with network access to the device's web management interface sends shell metacharacters inside JSON parameters to the /goform/formJsonAjaxReq endpoint, which fails to sanitize the input before passing it to the operating system. Successful exploitation lets the attacker run arbitrary OS commands with root privileges, giving full control of the router (traffic interception, configuration changes, or pivoting to connected networks). All LT15D devices on firmware through M7628NNxlSPv2xUI_v1.0.1802.10.08_P4 and LT21B devices on firmware through M7628xUSAxUIv2_v1.0.1481.15.02_P0 are affected. The flaw is not yet in CISA's KEV and no public proof-of-concept or confirmed in-the-wild exploitation is known, but the high EPSS score (39.7%, 99th percentile) indicates an elevated probability of exploitation within 30 days.
What to do: Check devices for the affected firmware builds and, when the vendor releases one, upgrade to a firmware version newer than M7628NNxlSPv2xUI_v1.0.1802.10.08_P4 (LT15D) or M7628xUSAxUIv2_v1.0.1481.15.02_P0 (LT21B). Until then, disable or firewall WAN-side remote management so /goform/formJsonAjaxReq is reachable only from trusted LAN networks, and monitor devices for signs of unexpected commands or configuration changes.
| Tuoshi (Dionlink) LT15D 4G Wi-Fi router | through M7628NNxlSPv2xUI_v1.0.1802.10.08_P4 |
| Tuoshi (Dionlink) LT21B 4G Wi-Fi router | through M7628xUSAxUIv2_v1.0.1481.15.02_P0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue was discovered on Tuoshi/Dionlink LT15D 4G Wi-Fi devices through M7628NNxlSPv2xUI_v1.0.1802.10.08_P4 and LT21B devices through M7628xUSAxUIv2_v1.0.1481.15.02_P0. A unauthenticated remote attacker with network access can exploit a command injection vulnerability. The /goform/formJsonAjaxReq endpoint fails to sanitize shell metacharacters sent via JSON parameters, thus allowing attackers to execute arbitrary OS commands with root privileges.
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.