Impact
AJCloud AJY IPC firmware before version 01.10715.11.37 allows an attacker to supply path traversal characters in an HTTP request to the jdbhttpd service. This flaw enables unauthenticated remote actors to read arbitrary files stored on the device with root permissions. The attacker can obtain sensitive data such as cleartext RTSP credentials, Wi‑Fi SSID and pre‑shared key, device serial number, and cloud binding parameters, effectively compromising confidentiality of the device without any authentication requirements.
Affected Systems
The vulnerability affects AJCloud AJY IPC firmware devices running any firmware prior to 01.10715.11.37. Users should verify the firmware version on their devices and identify those that have not been updated to this or later releases.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and the lack of an EPSS score suggests limited public exploitation data but a non‑negligible risk. The flaw is not listed in CISA's KEV catalog, yet the direct remote access and root‑level file read provide a severe threat that could be leveraged for further attacks or persistence. Attackers can exploit the issue by simply sending crafted HTTP requests to port 80 without any authentication or special setup.
OpenCVE Enrichment