Junglewise Threat Intelligence

CVE-2026-75340: JetLinks Community Server-Side Request Forgery in device metadata import

CVE-2026-75340 · Severity: critical · CVSS 9.1 · Published 2026-08-26

Executive brief

JetLinks Community is an open-source IoT platform used to manage connected devices. The device metadata import feature contains a server-side request forgery (SSRF) vulnerability that allows authenticated attackers to make the server initiate requests to internal systems, potentially scanning networks, accessing internal services, or reading local files. The vulnerability is exploitable by default due to a hardcoded admin password.

Technical details

The /device/instance/{productId}/property-metadata/import endpoint accepts a user-supplied fileUrl parameter and passes it directly to an input stream handler without validation. If the URL starts with "http", it is fetched via WebClient (enabling SSRF), otherwise it is opened as a local file via FileInputStream (enabling arbitrary local file read). An attacker who authenticates with default credentials (admin / JetLinks.C0mmVn1ty) can craft requests to scan internal networks, probe open ports, access internal services, or read local files on the server. No network-level authentication bypass is required—exploitation depends only on the default credentials not being changed.

Affected products

  • JetLinks JetLinks Community <= 2.11

Timeline

  • 2026-08-26: disclosed

References