CVE-2026-56718
largeUnauthenticated Path Traversal File Disclosure in AJCloud AJY IPC Camera Firmware
AJCloud AJY IPC camera firmware before version 01.10715.11.37 contains a path traversal vulnerability (CWE-22) in the jdbhttpd web service. An unauthenticated remote attacker can send a crafted HTTP request with traversal sequences in the URI to TCP port 80, causing the service to return files from anywhere on the device's filesystem. Because the flaw allows reads with root privileges, an attacker can retrieve highly sensitive files, including cleartext RTSP credentials, the Wi-Fi SSID and pre-shared key, the device serial number, and cloud binding parameters, potentially enabling further compromise of the camera and the network it joins. Any AJY IPC device running affected firmware is vulnerable, with risk highest for cameras whose port 80 is reachable from the internet. No public proof-of-concept or confirmed in-the-wild exploitation is known; EPSS estimates a 0.6% chance of exploitation in the next 30 days, and the issue is not in CISA's KEV catalog.
What to do: Upgrade AJY IPC firmware to version 01.10715.11.37 or later. Until patched, restrict TCP port 80 on the camera to trusted networks or a VPN rather than exposing it directly to the internet, and treat stored Wi-Fi and RTSP credentials as potentially compromised—rotate the Wi-Fi passphrase and RTSP passwords after updating. Review camera logs for HTTP requests to port 80 containing traversal sequences (e.g., ../) as a sign of probing or exploitation.
| AJCloud AJY IPC firmware (jdbhttpd web service) | all versions prior to 01.10715.11.37 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by supplying path traversal sequences in the HTTP request URI. Attackers can send crafted HTTP requests to port 80 without authentication to access sensitive files including cleartext RTSP credentials, Wi-Fi SSID and pre-shared key, device serial number, and cloud binding parameters.
- Weakness
- CWE-22
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.