ZeroHour

CVE-2026-56718

large

Unauthenticated Path Traversal File Disclosure in AJCloud AJY IPC Camera Firmware

CVSS 4.0
8.7 high
EPSS
<1%p48
Published
()
Modified
AI analysis

AJCloud AJY IPC camera firmware before version 01.10715.11.37 contains a path traversal vulnerability (CWE-22) in the jdbhttpd web service. An unauthenticated remote attacker can send a crafted HTTP request with traversal sequences in the URI to TCP port 80, causing the service to return files from anywhere on the device's filesystem. Because the flaw allows reads with root privileges, an attacker can retrieve highly sensitive files, including cleartext RTSP credentials, the Wi-Fi SSID and pre-shared key, the device serial number, and cloud binding parameters, potentially enabling further compromise of the camera and the network it joins. Any AJY IPC device running affected firmware is vulnerable, with risk highest for cameras whose port 80 is reachable from the internet. No public proof-of-concept or confirmed in-the-wild exploitation is known; EPSS estimates a 0.6% chance of exploitation in the next 30 days, and the issue is not in CISA's KEV catalog.

What to do: Upgrade AJY IPC firmware to version 01.10715.11.37 or later. Until patched, restrict TCP port 80 on the camera to trusted networks or a VPN rather than exposing it directly to the internet, and treat stored Wi-Fi and RTSP credentials as potentially compromised—rotate the Wi-Fi passphrase and RTSP passwords after updating. Review camera logs for HTTP requests to port 80 containing traversal sequences (e.g., ../) as a sign of probing or exploitation.

Affected
AJCloud AJY IPC firmware (jdbhttpd web service)all versions prior to 01.10715.11.37
Estimated exposure
large≈ tens of thousands of internet-exposed cameras (estimate; no public scan or install counts available) — No public active-install counts or internet-exposure scan data for AJY/AJCloud cameras are available, so this order-of-magnitude estimate rests on deployment patterns: AJCloud OEM firmware is embedded in high volumes of white-label…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by supplying path traversal sequences in the HTTP request URI. Attackers can send crafted HTTP requests to port 80 without authentication to access sensitive files including cleartext RTSP credentials, Wi-Fi SSID and pre-shared key, device serial number, and cloud binding parameters.

Weakness
CWE-22
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.