CVE 9.8 CRITICAL

CVE-2025-68706_CVE-2025-68706

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

A stack-based buffer overflow exists in the GoAhead-Webs HTTP daemon on KuWFi 4G LTE AC900 devices with firmware 1.0.13. The /goform/formMultiApnSetting handler uses sprintf() to copy the user-supplied pincode parameter into a fixed 132-byte stack buffer with no bounds checks. This allows an attacker to corrupt adjacent stack memory, crash the web server, and (under certain conditions) may enable arbitrary code execution.

AI Analysis

Stack-based buffer overflow in GoAhead-Webs HTTP daemon

Basic Information

ID CVE-2025-68706
Source mitre
Published Dec 29, 2025 at 00:00
Modified Dec 31, 2025 at 16:59

Affected Product

Vendor KuwFi
Product KuwFi 4G LTE AC900
Version 1.0.13
Affected Versions n/a n/a n/a

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor KuwFi
Product KuwFi 4G LTE AC900
Version 1.0.13

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.