CVE-2025-4635: Jct Airpointer

Medium severity, CVSS 6.6. EPSS: 0.4% chance of exploitation in the next 30 days.

A malicious user with administrative privileges in the web portal would be able to manipulate the Diagnostics module to obtain remote code execution on the local device as a low privileged user.

Affected products

  • Jct Airpointer: version 2.4.107-2 only

Published 2025-05-30. Last modified 2026-06-17.