Vulnerability Description
Jointelli 5G CPE 21H01 firmware JY_21H01_A3_v1.36 devices allow (blind) OS command injection. Multiple endpoints are vulnerable, including /ubus/?flag=set_WPS_pin and /ubus/?flag=netAppStar1 and /ubus/?flag=set_wifi_cfgs. This allows an authenticated attacker to execute arbitrary OS commands with root privileges via crafted inputs to the SSID, WPS, Traceroute, and Ping fields.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/actuator/cve/blob/main/Jointelli/CVE-2025-43978.txt
- https://github.com/actuator/cve/tree/main/Jointelli
- https://www.jointelli.com/cpe/5g-cpe-evo-4.html
- https://www.jointelli.com/product/25H01
FAQ
What is CVE-2025-43978?
CVE-2025-43978 is a vulnerability with a CVSS score of 7.4 (HIGH). Jointelli 5G CPE 21H01 firmware JY_21H01_A3_v1.36 devices allow (blind) OS command injection. Multiple endpoints are vulnerable, including /ubus/?flag=set_WPS_pin and /ubus/?flag=netAppStar1 and /ubus...
How severe is CVE-2025-43978?
CVE-2025-43978 has been rated HIGH with a CVSS base score of 7.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-43978?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.