VYPR

5G CPE 21H01

by Jointelli

CVEs (1)

  • CVE-2025-43978HigAug 5, 2025
    risk 0.48cvss 7.4epss 0.01

    Jointelli 5G CPE 21H01 firmware JY_21H01_A3_v1.36 devices allow (blind) OS command injection. Multiple endpoints are vulnerable, including /ubus/?flag=set_WPS_pin and /ubus/?flag=netAppStar1 and /ubus/?flag=set_wifi_cfgs. This allows an authenticated attacker to execute…