Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-43978

Опубликовано: 05 авг. 2025
Источник: nvd
CVSS3: 7.4
EPSS Низкий

Описание

Jointelli 5G CPE 21H01 firmware JY_21H01_A3_v1.36 devices allow (blind) OS command injection. Multiple endpoints are vulnerable, including /ubus/?flag=set_WPS_pin and /ubus/?flag=netAppStar1 and /ubus/?flag=set_wifi_cfgs. This allows an authenticated attacker to execute arbitrary OS commands with root privileges via crafted inputs to the SSID, WPS, Traceroute, and Ping fields.

EPSS

Процентиль: 27%
0.00098
Низкий

7.4 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.4
github
6 месяцев назад

Jointelli 5G CPE 21H01 firmware JY_21H01_A3_v1.36 devices allow (blind) OS command injection. Multiple endpoints are vulnerable, including /ubus/?flag=set_WPS_pin and /ubus/?flag=netAppStar1 and /ubus/?flag=set_wifi_cfgs. This allows an authenticated attacker to execute arbitrary OS commands with root privileges via crafted inputs to the SSID, WPS, Traceroute, and Ping fields.

EPSS

Процентиль: 27%
0.00098
Низкий

7.4 High

CVSS3

Дефекты

CWE-78