A stack-based buffer overflow exists in the GoAhead-Webs HTTP daemon on KuWFi 4G LTE AC900 devices with firmware 1.0.13. The /goform/formMultiApnSetting handler uses sprintf() to copy the user-supplied pincode parameter into a fixed 132-byte stack buffer with no bounds checks. This allows an attacker to corrupt adjacent stack memory, crash the web server, and (under certain conditions) may enable arbitrary code execution.
References
Configurations
Configuration 1 (hide)
| AND |
|
History
15 Jan 2026, 02:21
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://drive.proton.me/urls/HJCJYAC7JM#XtHcm3P7QaYk - Broken Link | |
| References | () https://github.com/actuator/cve/blob/main/Kuwfi/CVE-2025-68706.txt - Third Party Advisory | |
| References | () https://github.com/actuator/cve/tree/main/Kuwfi - Third Party Advisory | |
| References | () https://kuwfi.com/products/kuwfi-gigabit-wireless-router-4g-lte-wifi-router-dual-band-portable-wifi-modem-hotspot-64-user-with-gigabit-wan-lan-rj11-port - Product | |
| CPE | cpe:2.3:h:kuwfi:ac900:-:*:*:*:*:*:*:* cpe:2.3:o:kuwfi:ac900_firmware:1.0.13:*:*:*:*:*:*:* |
|
| First Time |
Kuwfi ac900 Firmware
Kuwfi ac900 Kuwfi |
31 Dec 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| CWE | CWE-121 |
29 Dec 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-29 19:15
Updated : 2026-01-15 02:21
NVD link : CVE-2025-68706
Mitre link : CVE-2025-68706
CVE.ORG link : CVE-2025-68706
JSON object : View
Products Affected
kuwfi
- ac900
- ac900_firmware
CWE
CWE-121
Stack-based Buffer Overflow
