9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
A stack-based buffer overflow exists in the GoAhead-Webs HTTP daemon on KuWFi 4G LTE AC900 devices with firmware 1.0.13. The /goform/formMultiApnSetting handler uses sprintf() to copy the user-supplied pincode parameter into a fixed 132-byte stack buffer with no bounds checks. This allows an attacker to corrupt adjacent stack memory, crash the web server, and (under certain conditions) may enable arbitrary code execution.
AI Analysis
Stack-based buffer overflow in GoAhead-Webs HTTP daemon
Basic Information
ID
CVE-2025-68706
Source
mitre
Published
Dec 29, 2025 at 00:00
Modified
Dec 31, 2025 at 16:59
Affected Product
Vendor
KuwFi
Product
KuwFi 4G LTE AC900
Version
1.0.13
Affected Versions
n/a n/a n/a
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
KuwFi
Product
KuwFi 4G LTE AC900
Version
1.0.13