KuWFi 4G LTE AC900 Router Cross-Site Request Forgery Vulnerability

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the KuWFi 4G LTE AC900 router, specifically in version 1.0.13. This vulnerability resides in the web management interface, where an attacker can manipulate an authenticated admin user into executing unauthorized actions. Such actions may include exploiting a command injection vulnerability in the 'formMultiApnSetting' endpoint, potentially leading to unauthorized changes in router configuration.

Impact

Exploitation of this vulnerability could allow for command injection, with the possibility of enabling unauthorized services such as Telnet, or making critical configuration changes on the router.

Reproduction

To reproduce this vulnerability, an attacker must trick an authenticated admin user into visiting a malicious webpage that contains an auto-submitted form. This form can be designed to send a POST request to the 'formMultiApnSetting' endpoint with a payload that exploits the command injection vulnerability, such as inserting a command to enable Telnet services.

Added: Aug 14, 2025, 3:22 PM
Updated: Aug 14, 2025, 4:55 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.7
remediation
0.0
relevance
0.4
threat
1.6
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.