Executive brief
JetLinks Community is an open-source IoT platform used to manage connected devices. The device metadata import feature contains a server-side request forgery (SSRF) vulnerability that allows authenticated attackers to make the server initiate requests to internal systems, potentially scanning networks, accessing internal services, or reading local files. The vulnerability is exploitable by default due to a hardcoded admin password.
Technical details
The /device/instance/{productId}/property-metadata/import endpoint accepts a user-supplied fileUrl parameter and passes it directly to an input stream handler without validation. If the URL starts with "http", it is fetched via WebClient (enabling SSRF), otherwise it is opened as a local file via FileInputStream (enabling arbitrary local file read). An attacker who authenticates with default credentials (admin / JetLinks.C0mmVn1ty) can craft requests to scan internal networks, probe open ports, access internal services, or read local files on the server. No network-level authentication bypass is required—exploitation depends only on the default credentials not being changed.
Affected products
- JetLinks JetLinks Community <= 2.11
Timeline
- 2026-08-26: disclosed