Impact
The vulnerability exists in the device metadata import interface /device/instance/{productId}/property‑metadata/import of JetLinks Community 2.11. An attacker can exploit the SSRF flaw to direct the server to send HTTP requests to arbitrary internal or external resources, potentially revealing sensitive data or facilitating further attacks.
Affected Systems
JetLinks Community version 2.11. No other product or vendor information is provided.
Risk and Exploitability
The published EPSS score is not available and the vulnerability is not listed in CISA KEV. Without a CVSS score, the severity cannot be precisely quantified from the CVE entry, but SSRF allows attackers to access internal systems and potentially pivot to more critical assets. The likely attack vector is local or network‑level, requiring access to the JetLinks server or a valid session to call the import endpoint.
OpenCVE Enrichment