CVE Explorer
CVE-2025-68706
A stack-based buffer overflow exists in the GoAhead-Webs HTTP daemon on KuWFi 4G LTE AC900 devices with firmware 1.0.13. The /goform/formMultiApnSetting handler uses sprintf() to copy the user-supplied pincode parameter into a fixed 132-byte stack buffer with no bounds checks. This allows an attacker to corrupt adjacent stack memory, crash the web server, and (under certain conditions) may enable arbitrary code execution.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"description":"n/a","lang":"en","type":"text"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:173f48d9d5a648e832684bac6e37caa308291f53696c6a431ed4c672864d3b57 · sha256:766242b11ba3dd14… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-121","description":"CWE-121 Stack-based Buffer Overflow","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:173f48d9d5a648e832684bac6e37caa308291f53696c6a431ed4c672864d3b57 · sha256:766242b11ba3dd14… · /containers/adp/0/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:173f48d9d5a648e832684bac6e37caa308291f53696c6a431ed4c672864d3b57 · sha256:766242b11ba3dd14… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:173f48d9d5a648e832684bac6e37caa308291f53696c6a431ed4c672864d3b57 · sha256:766242b11ba3dd14… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"description":"n/a","lang":"en","type":"text"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:173f48d9d5a648e832684bac6e37caa308291f53696c6a431ed4c672864d3b57 · sha256:766242b11ba3dd14… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-121","description":"CWE-121 Stack-based Buffer Overflow","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:173f48d9d5a648e832684bac6e37caa308291f53696c6a431ed4c672864d3b57 · sha256:766242b11ba3dd14… · /containers/adp/0/problemTypes/0/descriptions/0
Source references
4 source assertions{"url":"https://drive.proton.me/urls/HJCJYAC7JM#XtHcm3P7QaYk"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:173f48d9d5a648e832684bac6e37caa308291f53696c6a431ed4c672864d3b57 · sha256:766242b11ba3dd14… · /containers/cna/references/2
{"url":"https://github.com/actuator/cve/blob/main/Kuwfi/CVE-2025-68706.txt"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:173f48d9d5a648e832684bac6e37caa308291f53696c6a431ed4c672864d3b57 · sha256:766242b11ba3dd14… · /containers/cna/references/3
{"url":"https://github.com/actuator/cve/tree/main/Kuwfi"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:173f48d9d5a648e832684bac6e37caa308291f53696c6a431ed4c672864d3b57 · sha256:766242b11ba3dd14… · /containers/cna/references/1
{"url":"https://kuwfi.com/products/kuwfi-gigabit-wireless-router-4g-lte-wifi-router-dual-band-portable-wifi-modem-hotspot-64-user-with-gigabit-wan-lan-rj11-port"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:173f48d9d5a648e832684bac6e37caa308291f53696c6a431ed4c672864d3b57 · sha256:766242b11ba3dd14… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.