Description
JD Cloud NAS routers AX1800 (4.3.1.r4308 and earlier), AX3000 (4.3.1.r4318 and earlier), AX6600 (4.5.1.r4533 and earlier), BE6500 (4.4.1.r4308 and earlier), ER1 (4.5.1.r4518 and earlier), and ER2 (4.5.1.r4518 and earlier) contain an unauthorized remote command execution vulnerability.
Published: 2025-12-30
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Jan 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Jdcloud
Jdcloud ax1800
Jdcloud ax1800 Firmware
Jdcloud ax3000
Jdcloud ax3000 Firmware
Jdcloud ax6600
Jdcloud ax6600 Firmware
Jdcloud be6500
Jdcloud be6500 Firmware
Jdcloud er1
Jdcloud er1 Firmware
Jdcloud er2
Jdcloud er2 Firmware
CPEs cpe:2.3:h:jdcloud:ax1800:-:*:*:*:*:*:*:*
cpe:2.3:h:jdcloud:ax3000:-:*:*:*:*:*:*:*
cpe:2.3:h:jdcloud:ax6600:-:*:*:*:*:*:*:*
cpe:2.3:h:jdcloud:be6500:-:*:*:*:*:*:*:*
cpe:2.3:h:jdcloud:er1:-:*:*:*:*:*:*:*
cpe:2.3:h:jdcloud:er2:-:*:*:*:*:*:*:*
cpe:2.3:o:jdcloud:ax1800_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:jdcloud:ax3000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:jdcloud:ax6600_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:jdcloud:be6500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:jdcloud:er1_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:jdcloud:er2_firmware:*:*:*:*:*:*:*:*
Vendors & Products Jdcloud
Jdcloud ax1800
Jdcloud ax1800 Firmware
Jdcloud ax3000
Jdcloud ax3000 Firmware
Jdcloud ax6600
Jdcloud ax6600 Firmware
Jdcloud be6500
Jdcloud be6500 Firmware
Jdcloud er1
Jdcloud er1 Firmware
Jdcloud er2
Jdcloud er2 Firmware
References

Fri, 02 Jan 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 30 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Description JD Cloud NAS routers AX1800 (4.3.1.r4308 and earlier), AX3000 (4.3.1.r4318 and earlier), AX6600 (4.5.1.r4533 and earlier), BE6500 (4.4.1.r4308 and earlier), ER1 (4.5.1.r4518 and earlier), and ER2 (4.5.1.r4518 and earlier) contain an unauthorized remote command execution vulnerability.
References

Subscriptions

Jdcloud Ax1800 Ax1800 Firmware Ax3000 Ax3000 Firmware Ax6600 Ax6600 Firmware Be6500 Be6500 Firmware Er1 Er1 Firmware Er2 Er2 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-01-02T18:10:23.863Z

Reserved: 2025-12-08T00:00:00.000Z

Link: CVE-2025-66848

cve-icon Vulnrichment

Updated: 2026-01-02T16:29:11.019Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-30T17:15:43.357

Modified: 2026-01-09T19:57:09.533

Link: CVE-2025-66848

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses