CVE-2024-53944 Details
Description
An issue was discovered on Tuoshi/Dionlink LT15D 4G Wi-Fi devices through M7628NNxlSPv2xUI_v1.0.1802.10.08_P4 and LT21B devices through M7628xUSAxUIv2_v1.0.1481.15.02_P0. A unauthenticated remote attacker with network access can exploit a command injection vulnerability. The /goform/formJsonAjaxReq endpoint fails to sanitize shell metacharacters sent via JSON parameters, thus allowing attackers to execute arbitrary OS commands with root privileges.
A command injection vulnerability has been identified in Tuoshi/Dionlink LT15D 4G Wi-Fi devices running firmware M7628NNxlSPv2xUI_v1.0.1802.10.08_P4, and LT21B devices with firmware M7628xUSAxUIv2_v1.0.1481.15.02_P0. This vulnerability allows unauthenticated remote attackers with network access to execute arbitrary operating system commands with root privileges. The issue arises because the /goform/formJsonAjaxReq endpoint does not properly sanitize shell metacharacters in JSON parameters, enabling command injection exploitation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 27, 2025CISA-ADP
Assessed Mar 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Tuoshi LT15D | All versions |
CPE
Remediation
| |
| Tuoshi LT21B | M7628xUSAxUIv2_v1.0.1481.15.02_P0 |
CPE
Remediation
| |
| Tuoshi M7628NNxlSPv2xUI | All versions |
CPE
Remediation
| |
| Tuoshi M7628xUSAxUI | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 4, 2025 | CVE Modified | CISA-ADP |
| Feb 27, 2025 | New CVE Received | [email protected] |
Volerion