Sceawere

Vulnerability Detail

CVE-2026-56718UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

AJCloud AJY Path Traversal

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
AJCloud
Product
AJY IPC Firmware
Attack Type
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by supplying path traversal sequences in the HTTP request URI. Attackers can send crafted HTTP requests to port 80 without authentication to access sensitive files including cleartext RTSP credentials, Wi-Fi SSID and pre-shared key, device serial number, and cloud binding parameters.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-30T21:16:34.160Z",
  "pubdate": "2026-08-30T21:16:34.160Z",
  "executiveSummary": "The AJCloud AJY IPC firmware, specifically versions prior to 01.10715.11.37, contains a critical path traversal vulnerability within the jdbhttpd web service. This security flaw allows unauthenticated remote attackers to bypass access controls and retrieve arbitrary files from the underlying file system with root-level privileges.\nThe vulnerability stems from improper validation of user-supplied input within the HTTP request URI, permitting the inclusion of directory traversal sequences (e.g., ../). By successfully manipulating the request path, an attacker can access sensitive system configurations, including RTSP credentials, Wi-Fi network credentials (SSID and pre-shared keys), device serial numbers, and cloud synchronization parameters.\nThe risk implication is severe, as the compromise of these credentials facilitates unauthorized surveillance, potential interception of video streams, and lateral movement within the local network environment. Exploitation requires only network connectivity to port 80 and does not necessitate prior authentication, making the device highly susceptible to automated exploitation attempts.",
  "technicalDetails": "The vulnerability resides in the jdbhttpd web server component utilized by the AJCloud AJY IPC firmware. The flaw is fundamentally a lack of input sanitization during the processing of HTTP GET requests. When the web service receives a request, the server fails to properly neutralize dot-dot-slash (../) sequences within the URI, allowing the request to escape the intended document root directory.\nThe attack flow begins with an unauthenticated actor sending a crafted HTTP request to port 80. By injecting standard directory traversal payloads into the resource path, the attacker can traverse the file system hierarchy. Because the jdbhttpd process operates with root privileges, the server returns the contents of sensitive system files to the requester as part of the HTTP response body.\nKey files targeted during exploitation include configuration files that store plaintext credentials for RTSP streaming, Wi-Fi authentication details (SSID and PSK), and device-specific identifiers. The extraction of RTSP credentials effectively allows an attacker to bypass authentication mechanisms for real-time video surveillance feeds. Furthermore, the recovery of Wi-Fi credentials grants the attacker the ability to maintain persistence or pivot into the victim's local area network.\nThis vulnerability is particularly dangerous due to the lack of an authentication barrier, as the jdbhttpd service exposes this endpoint publicly by default. The impact post-exploitation extends beyond the immediate device, as the leaked cloud binding parameters could be leveraged to gain unauthorized access to the victim’s cloud-hosted management interface, effectively compromising the remote monitoring ecosystem associated with the hardware.\nAffected versions include all firmware iterations prior to 01.10715.11.37. The technical requirement for successful exploitation is limited to a reachable network path to the device's web management port and the ability to forge HTTP requests, requiring no specialized knowledge of the target's internal state beyond the path of the desired configuration files."
}
CVE-2026-56718: AJCloud AJY Path Traversal (HIGH Severity, CVSS: 7.5) - Sceawere