KuWFi GC111 Telnet Service Exposure Vulnerability Allowing Remote Access and Privilege Escalation

Vulnerability

A vulnerability exists in KuWFi GC111 devices running the GC111-GL-LM321_V3.0_20191211 firmware. The issue arises because the TELNET service is enabled by default, accessible over the WAN interface, and does not require authentication. This configuration allows remote access to the device with root privileges. Additionally, there is no option in the device's graphical user interface to disable the TELNET service, leaving the device persistently vulnerable to unauthorized access and privilege escalation.

Impact

Exploitation of this vulnerability allows for remote access to the device via the TELNET service with root privileges, without the need for authentication. This access could be used to execute commands on the device, potentially leading to unauthorized changes or access to sensitive information. Furthermore, according to the vulnerability description, this issue could be exploited to cause a denial-of-service.

Added: Aug 13, 2025, 8:28 PM
Updated: Aug 13, 2025, 8:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
7.4
remediation
0.0
relevance
0.3
threat
0.0
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.