Path Traversal Vulnerability in AJCloud AJY IPC Firmware
CVE-2026-56718
8.7HIGH
What is CVE-2026-56718?
The AJCloud AJY IPC firmware is susceptible to a path traversal vulnerability within the jdbhttpd web service. This flaw permits unauthorized remote adversaries to exploit the weakness via crafted HTTP requests transmitted to port 80. By utilizing path traversal sequences in the HTTP request URI, attackers can gain access to sensitive files residing on the device with root-level privileges. Among the data that may be compromised are plaintext RTSP credentials, Wi-Fi SSID and pre-shared keys, device serial numbers, and critical cloud binding parameters.
Affected Version(s)
AJY IPC Firmware 0
