CVE-2025-43978

HIGH7.4/ 10.0
Share:
Published: August 5, 2025 at 05:15 PM
Modified: August 5, 2025 at 09:06 PM
Source: cve@mitre.org

Vulnerability Description

Jointelli 5G CPE 21H01 firmware JY_21H01_A3_v1.36 devices allow (blind) OS command injection. Multiple endpoints are vulnerable, including /ubus/?flag=set_WPS_pin and /ubus/?flag=netAppStar1 and /ubus/?flag=set_wifi_cfgs. This allows an authenticated attacker to execute arbitrary OS commands with root privileges via crafted inputs to the SSID, WPS, Traceroute, and Ping fields.

CVSS Metrics

Base Score
7.4
Severity
HIGH
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses (CWE)

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0