ZeroHour

CVE-2025-43984

niche

Unauthenticated Root OS Command Injection in KuWFi GC111 Routers

CVSS 3.1
9.8 critical
EPSS
20%p97
Published
()
Modified
AI analysis

CVE-2025-43984 is an unauthenticated OS command injection (CWE-78) in the web management interface of KuWFi GC111 devices, reachable via the /goform/goform_set_cmd_process endpoint. A remote attacker triggers it by sending a crafted POST request containing a malicious SSID parameter, with no credentials or user interaction required. Successful exploitation executes arbitrary operating-system commands with root privileges, granting full control of the device, including its configuration and network traffic. Affected users are those running GC111 hardware version CPE-LM321_V3.2 with software version GC111-GL-LM321_V3.0_20191211. The flaw is not yet on CISA's KEV list and no public proof-of-concept is known, but its EPSS score of ~20.2% (97th percentile) indicates an elevated likelihood of exploitation within the next 30 days.

What to do: Minimize exposure by disabling WAN-side access to the device's management interface and restricting it to trusted management hosts via firewall/ACL rules. Check whether your GC111 runs the affected software version (GC111-GL-LM321_V3.0_20191211 on hardware CPE-LM321_V3.2) and contact KuWFi for patched firmware, as no fixed version is specified in the advisory. In the meantime, monitor logs for unauthenticated POST requests to /goform/goform_set_cmd_process containing unusual characters or commands in the SSID parameter.

Affected
KuWFi GC111Hardware Version CPE-LM321_V3.2 with Software Version GC111-GL-LM321_V3.0_20191211 (other builds not specified in the advisory)
Estimated exposure
nichelikely in the low thousands of exposed devices at most (estimate; no public install-base or scan data for this specific firmware build) — KuWFi is a small-budget 4G CPE vendor and the flaw is scoped to a single 2019 hardware/software build of the GC111, so the population of internet-reachable vulnerable units is plausibly in the thousands rather than hundreds of thousands,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered on KuWFi GC111 devices (Hardware Version: CPE-LM321_V3.2, Software Version: GC111-GL-LM321_V3.0_20191211). They are vulnerable to unauthenticated /goform/goform_set_cmd_process requests. A crafted POST request, using the SSID parameter, allows remote attackers to execute arbitrary OS commands with root privileges.

Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.