PT-2025-31947 · Firstnum · Firstnum Jc21A-04

Actuator

·

Published

2025-08-05

·

Updated

2025-08-05

·

CVE-2025-43980

CVSS v3.1
6.5
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Name of the Vulnerable Software and Affected Versions:

FIRSTNUM JC21A-04 devices versions through 2.01ME/FN

Description:

FIRSTNUM JC21A-04 devices enable the SSH service by default with the credentials `root`/`admin`. The graphical user interface (GUI) does not provide a method to disable this account.

Recommendations:

For versions through 2.01ME/FN, change the default `root` account password or disable the SSH service.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-43980

Affected Products

Firstnum Jc21A-04