KuWFi CPF908-CP5 WEB5.0_LCD_20210125 devices have multiple unauthenticated access control vulnerabilities within goform/goform_set_cmd_process and goform/goform_get_cmd_process. These allow an unauthenticated attacker to retrieve sensitive information (including the device admin username and password), modify critical device settings, and send arbitrary SMS messages.
References
Configurations
No configuration.
History
15 Aug 2025, 13:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
CWE | CWE-306 |
14 Aug 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-08-14 15:15
Updated : 2025-08-15 13:15
NVD link : CVE-2025-43983
Mitre link : CVE-2025-43983
CVE.ORG link : CVE-2025-43983
JSON object : View
Products Affected
No product.
CWE
CWE-306
Missing Authentication for Critical Function