peter bassill · operator
$ cve CVE-2025-68706 JSON

CVE-2025-68706

9.8
CRITICAL · CVSS 3.1 · EPSS 5% (pctl 92)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A stack-based buffer overflow exists in the GoAhead-Webs HTTP daemon on KuWFi 4G LTE AC900 devices with firmware 1.0.13. The /goform/formMultiApnSetting handler uses sprintf() to copy the user-supplied pincode parameter into a fixed 132-byte stack buffer with no bounds checks. This allows an attacker to corrupt adjacent stack memory, crash the web server, and (under certain conditions) may enable arbitrary code execution.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.97% — more likely to be exploited than 92% of all CVEs
WeaknessCWE-121
On CISA KEVno
Public exploitnone known
Published2025-12-29
Last modified2026-06-17

Affected (2)

VendorProduct
kuwfiac900
kuwfiac900 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD