CVE-2025-43984
nicheUnauthenticated Root OS Command Injection in KuWFi GC111 Routers
CVE-2025-43984 is an unauthenticated OS command injection (CWE-78) in the web management interface of KuWFi GC111 devices, reachable via the /goform/goform_set_cmd_process endpoint. A remote attacker triggers it by sending a crafted POST request containing a malicious SSID parameter, with no credentials or user interaction required. Successful exploitation executes arbitrary operating-system commands with root privileges, granting full control of the device, including its configuration and network traffic. Affected users are those running GC111 hardware version CPE-LM321_V3.2 with software version GC111-GL-LM321_V3.0_20191211. The flaw is not yet on CISA's KEV list and no public proof-of-concept is known, but its EPSS score of ~20.2% (97th percentile) indicates an elevated likelihood of exploitation within the next 30 days.
What to do: Minimize exposure by disabling WAN-side access to the device's management interface and restricting it to trusted management hosts via firewall/ACL rules. Check whether your GC111 runs the affected software version (GC111-GL-LM321_V3.0_20191211 on hardware CPE-LM321_V3.2) and contact KuWFi for patched firmware, as no fixed version is specified in the advisory. In the meantime, monitor logs for unauthenticated POST requests to /goform/goform_set_cmd_process containing unusual characters or commands in the SSID parameter.
| KuWFi GC111 | Hardware Version CPE-LM321_V3.2 with Software Version GC111-GL-LM321_V3.0_20191211 (other builds not specified in the advisory) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue was discovered on KuWFi GC111 devices (Hardware Version: CPE-LM321_V3.2, Software Version: GC111-GL-LM321_V3.0_20191211). They are vulnerable to unauthenticated /goform/goform_set_cmd_process requests. A crafted POST request, using the SSID parameter, allows remote attackers to execute arbitrary OS commands with root privileges.
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.