CVE-2025-68706

A stack-based buffer overflow exists in the GoAhead-Webs HTTP daemon on KuWFi 4G LTE AC900 devices with firmware 1.0.13. The /goform/formMultiApnSetting handler uses sprintf() to copy the user-supplied pincode parameter into a fixed 132-byte stack buffer with no bounds checks. This allows an attacker to corrupt adjacent stack memory, crash the web server, and (under certain conditions) may enable arbitrary code execution.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:kuwfi:ac900_firmware:1.0.13:*:*:*:*:*:*:*
cpe:2.3:h:kuwfi:ac900:-:*:*:*:*:*:*:*

History

15 Jan 2026, 02:21

Type Values Removed Values Added
References () https://drive.proton.me/urls/HJCJYAC7JM#XtHcm3P7QaYk - () https://drive.proton.me/urls/HJCJYAC7JM#XtHcm3P7QaYk - Broken Link
References () https://github.com/actuator/cve/blob/main/Kuwfi/CVE-2025-68706.txt - () https://github.com/actuator/cve/blob/main/Kuwfi/CVE-2025-68706.txt - Third Party Advisory
References () https://github.com/actuator/cve/tree/main/Kuwfi - () https://github.com/actuator/cve/tree/main/Kuwfi - Third Party Advisory
References () https://kuwfi.com/products/kuwfi-gigabit-wireless-router-4g-lte-wifi-router-dual-band-portable-wifi-modem-hotspot-64-user-with-gigabit-wan-lan-rj11-port - () https://kuwfi.com/products/kuwfi-gigabit-wireless-router-4g-lte-wifi-router-dual-band-portable-wifi-modem-hotspot-64-user-with-gigabit-wan-lan-rj11-port - Product
CPE cpe:2.3:h:kuwfi:ac900:-:*:*:*:*:*:*:*
cpe:2.3:o:kuwfi:ac900_firmware:1.0.13:*:*:*:*:*:*:*
First Time Kuwfi ac900 Firmware
Kuwfi ac900
Kuwfi

31 Dec 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-121

29 Dec 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-29 19:15

Updated : 2026-01-15 02:21


NVD link : CVE-2025-68706

Mitre link : CVE-2025-68706

CVE.ORG link : CVE-2025-68706


JSON object : View

Products Affected

kuwfi

  • ac900
  • ac900_firmware
CWE
CWE-121

Stack-based Buffer Overflow