← Back to browse · API

CVE-2025-43984

Severity
CRITICAL
CVSS
9.8
EPSS
0.19302
Risk score
45.96
CISA KEV
No
PoC
No
Published
2025-08-14
Modified
2025-08-15
First seen
2026-08-07
Aliases
EUVD-2025-24818, GHSA-RPVV-C9R8-23VH
Products
n/a:n/a n/a
Sources
euvd EUVD-2025-24818

Description

An issue was discovered on KuWFi GC111 devices (Hardware Version: CPE-LM321_V3.2, Software Version: GC111-GL-LM321_V3.0_20191211). They are vulnerable to unauthenticated /goform/goform_set_cmd_process requests. A crafted POST request, using the SSID parameter, allows remote attackers to execute arbitrary OS commands with root privileges.

References