CVE-2025-43979

7.4

FIRSTNUM · JC21A-04

A command injection vulnerability in FIRSTNUM JC21A-04 devices allows authenticated attackers to execute arbitrary OS system commands with root privileges via the xml_action.cgi endpoint.

Executive summary

An authenticated command injection vulnerability in FIRSTNUM JC21A-04 devices allows attackers to achieve full system compromise with root privileges.

Vulnerability

The device is vulnerable to OS command injection via the xml_action.cgi?method= endpoint, which fails to properly sanitize user input, allowing authenticated attackers to execute arbitrary commands as the root user.

Business impact

The ability to execute commands with root privileges grants an attacker total control over the affected hardware. This creates a significant risk of data exfiltration, permanent device bricking, or the integration of the device into a botnet for further attacks. Given the CVSS score of 7.4, this vulnerability represents a high risk to organizational infrastructure that relies on these units.

Remediation

Immediate Action: Contact the vendor immediately to obtain firmware updates that address this command injection flaw and apply them to all affected devices.

Proactive Monitoring: Review access logs for the xml_action.cgi endpoint to identify suspicious or unusual POST requests containing shell metacharacters.

Compensating Controls: If a patch is unavailable, restrict network access to the management interface of the JC21A-04 devices to trusted management subnets only via a firewall or ACL.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the research write-up referenced in the CVE record.

Analyst recommendation

This vulnerability presents a high risk due to the potential for total system compromise with administrative privileges. Administrators should prioritize identifying all instances of the affected JC21A-04 hardware within the network and apply vendor-provided patches as soon as they become available. Until remediation is complete, isolate these devices from untrusted network segments to prevent unauthorized access.

Sources