Vulnerability Description
KuWFi CPF908-CP5 WEB5.0_LCD_20210125 devices have multiple unauthenticated access control vulnerabilities within goform/goform_set_cmd_process and goform/goform_get_cmd_process. These allow an unauthenticated attacker to retrieve sensitive information (including the device admin username and password), modify critical device settings, and send arbitrary SMS messages.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
- https://drive.proton.me/urls/CN629YJ3F4#NUgX6IB4clos
- https://github.com/actuator/cve/blob/main/Kuwfi/CVE-2025-43983.txt
- https://github.com/actuator/cve/tree/main/KuWfi
FAQ
What is CVE-2025-43983?
CVE-2025-43983 is a vulnerability with a CVSS score of 9.1 (CRITICAL). KuWFi CPF908-CP5 WEB5.0_LCD_20210125 devices have multiple unauthenticated access control vulnerabilities within goform/goform_set_cmd_process and goform/goform_get_cmd_process. These allow an unauthe...
How severe is CVE-2025-43983?
CVE-2025-43983 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-43983?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.