Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-56718: AJCloud cameras expose sensitive files to anyone
CVE-2026-56718 · published 4 days ago
Summary
Older AJCloud camera firmware lets anyone on the network request files stored on the device without logging in. This can reveal passwords, Wi‑Fi keys, device serial numbers and other private settings. Update the cameras to the latest firmware or disable the web service if you cannot upgrade.
What to do
- Update ajcloud ajy ipc firmware to version 01.10715.11.37 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ajcloud | ajy ipc firmware | < 01.10715.11.37 |
Original advisory text
AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files wit...
AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by supplying path traversal sequences in the HTTP request URI. Attackers can send crafted HTTP requests to port 80 without authentication to access sensitive files including cleartext RTSP credentials, Wi-Fi SSID and pre-shared key, device serial number, and cloud binding parameters.
References
- https://www.ajcloud.net/ product
- https://www.vulncheck.com/advisories/ajcloud-ajy-ipc-firmware-path-traversal-via... third-party-advisory
Severity
8.7
High
CVSS 3.1: 7.5 (MITRE)
Exploitation
EPSS <1%
Type
CWE-22Path Traversal
Timeline
Published30 Aug 2026
Updated2 Sep 2026
First seen30 Aug 2026
Monitor software like this
Free during beta