CVE-2024-53944

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 27, 2025
Updated: Mar 4, 2025
CWE ID 94

Summary

CVE-2024-53944 is a newly disclosed vulnerability affecting Tuoshi/Dionlink LT15D and LT21B 4G Wi-Fi devices. The issue lies in the unsecured handling of JSON parameters in the /goform/formJsonAjaxReq endpoint. A remote, unauthenticated attacker with network access can capitalize on this command injection vulnerability to execute arbitrary OS commands with root privileges on impacted devices, including the M7628NNxlSPv2xUI_v1.0.1802.10.08_P4 and M7628xUSAxUIv2_v1.0.1481.15.02_P0 firmware versions.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share