← Back to browse · API

CVE-2024-53944

Severity
CRITICAL
CVSS
9.8
EPSS
0.39682
Risk score
53.09
CISA KEV
No
PoC
No
Published
2025-02-27
Modified
2025-03-04
First seen
2026-08-07
Aliases
EUVD-2025-6002, GHSA-3R6H-CMR9-36J6
Products
n/a:n/a n/a
Sources
euvd EUVD-2025-6002

Description

An issue was discovered on Tuoshi/Dionlink LT15D 4G Wi-Fi devices through M7628NNxlSPv2xUI_v1.0.1802.10.08_P4 and LT21B devices through M7628xUSAxUIv2_v1.0.1481.15.02_P0. A unauthenticated remote attacker with network access can exploit a command injection vulnerability. The /goform/formJsonAjaxReq endpoint fails to sanitize shell metacharacters sent via JSON parameters, thus allowing attackers to execute arbitrary OS commands with root privileges.

References