Junglewise Threat Intelligence

CVE-2026-58452: JAIOTlink C492A-W6 OS command injection in SetMAC endpoint

CVE-2026-58452 · Severity: high · CVSS 8.8 · Published 2026-07-01

Technologies: JAIOTlink C492A-W6 Wi-Fi IP Camera. Vendors: JAIOTlink.

Executive brief

JAIOTlink Wi-Fi IP cameras contain a security flaw that allows an authorized user to take full control of the device. By sending a specially crafted command to the camera's management interface, an attacker can execute arbitrary code, potentially leading to unauthorized surveillance, data theft, or use of the device in further network attacks. This impact is significant as it compromises the privacy and operational integrity of the camera system.

Technical details

An OS command injection vulnerability exists in the JAIOTlink C492A-W6 Wi-Fi IP camera firmware version 4.8.30.57701411. The flaw is located in the HTTP PUT NetSDK/Factory SetMAC endpoint, specifically within the handling of the 'Wireless' parameter. While the application attempts to validate the input using sscanf(), it only performs partial validation. An attacker can bypass this by providing a valid MAC-like prefix followed by a semicolon and a shell payload. This unsanitized input is subsequently passed to an 'echo' command executed via a system() wrapper, allowing for remote code execution with the privileges of the web service. Authentication is required to reach the vulnerable endpoint.

Affected products

  • JAIOTlink C492A-W6 Wi-Fi IP Camera 4.8.30.57701411

Timeline

  • 2026-07-01: advisory: NVD and VulnCheck published the advisory.

References

Related threats