CVE-2025-43978 | Jointelli 5G CPE 21H01 JY_21H01_A3_v1.36 /ubus/?flag=set_WPS_pin SSID/WPS/Traceroute/Ping os command injection
A vulnerability, which was classified as critical, was found in Jointelli 5G CPE 21H01 JY_21H01_A3_v1.36. Affected is an unknown function of the file /ubus/?flag=set_WPS_pin. The manipulation of the argument SSID/WPS/Traceroute/Ping leads to os command injection.
This vulnerability is traded as CVE-2025-43978. The attack needs to be done within the local network. There is no exploit available.