Junglewise Threat Intelligence

CVE-2026-56718: AJCloud AJY IPC firmware path traversal in jdbhttpd

CVE-2026-56718 · Severity: high · CVSS 7.5 · Published 2026-08-30

Executive brief

AJCloud AJY IP cameras contain a web service vulnerability that allows attackers to read sensitive files without a password. By sending specially crafted requests over the network, attackers can access stored credentials for streaming video, Wi-Fi passwords, device serial numbers, and cloud account bindings—compromising customer privacy and enabling account hijacking.

Technical details

The vulnerability is a path traversal flaw in the jdbhttpd web service running on port 80 of AJY IPC firmware versions prior to 01.10715.11.37. Unauthenticated remote attackers can craft HTTP requests with path traversal sequences (e.g., ../) in the URI to bypass directory restrictions and read arbitrary files with root privileges. The attack requires no authentication and is network-reachable from any source; exploitation allows exfiltration of cleartext RTSP credentials, Wi-Fi SSID/PSK, device serial numbers, and cloud binding parameters. Patched versions are available from the vendor.

Affected products

  • AJCloud AJY IPC firmware prior to 01.10715.11.37

Timeline

  • 2026-08-30: disclosed

References