Junglewise Threat Intelligence

CVE-2026-58454: JAIOTlink C492A-W6 remote code execution in Anyka config endpoint

CVE-2026-58454 · Severity: high · CVSS 7.5 · Published 2026-07-01

Technologies: JAIOTlink C492A-W6 Wi-Fi IP Camera. Vendors: JAIOTlink.

Executive brief

JAIOTlink Wi-Fi IP cameras, used for remote video monitoring, contain a security flaw that allows an authorized user to take full control of the device. By uploading a malicious script to the camera's internal storage, an attacker can force the device to execute that script. This results in a permanent compromise of the camera that remains active even after the device is restarted, potentially allowing unauthorized access to video feeds or the local network.

Technical details

A remote code execution vulnerability exists in JAIOTlink C492A-W6 Wi-Fi IP cameras due to improper control of code generation (CWE-94). An authenticated attacker can exploit this by writing a malicious shell script to the writable persistent JFFS2 storage path. The attacker then triggers the execution of this script by sending a request to the authenticated /Anyka/config HTTP endpoint, which invokes the script via the popen() function. This flaw allows for persistent remote code execution that survives device reboots. The attack requires network access and valid user credentials, though it is classified as high complexity due to the multi-step staging process.

Affected products

  • JAIOTlink C492A-W6 Wi-Fi IP Camera 4.8.30.57701411

Timeline

  • 2026-07-01: advisory: Vulnerability disclosed by VulnCheck and NVD

References

Related threats