Executive brief
Multiple JD Cloud NAS router models are affected by a critical security flaw that allows unauthorized individuals to execute commands remotely. These devices are typically used for home and small business networking and data storage. An attacker could exploit this vulnerability to take full control of the router, potentially leading to the theft of stored data, monitoring of network traffic, or complete service disruption.
Technical details
A remote command execution (RCE) vulnerability exists in several JD Cloud NAS router models, including the AX1800, AX3000, AX6600, BE6500, ER1, and ER2. The flaw is classified as a code injection vulnerability (CWE-94) resulting from improper control of code generation. An unauthenticated attacker can exploit this over the network without user interaction to execute arbitrary commands with high privileges. This can lead to a total loss of confidentiality, integrity, and availability. Affected firmware versions range across different models, generally impacting versions up to late 2025 releases.
Affected products
- JD Cloud AX1800 Firmware up to and including 4.3.1.r4308
- JD Cloud AX3000 Firmware up to and including 4.3.1.r4318
- JD Cloud AX6600 Firmware up to and including 4.5.1.r4533
- JD Cloud BE6500 Firmware up to and including 4.4.1.r4308
- JD Cloud ER1 Firmware up to and including 4.5.1.r4518
- JD Cloud ER2 Firmware up to and including 4.5.1.r4518
Timeline
- 2025-12-30: advisory: Initial disclosure by MITRE/NVD