Impact
The vulnerability exists in the device metadata import interface /device/instance/{productId}/property-metadata/import of JetLinks Community 2.11. An attacker can exploit the SSRF flaw to direct the JetLinks server to send HTTP requests to arbitrary internal or external resources, potentially revealing sensitive data or facilitating further attacks.
Affected Systems
JetLinks Community version 2.11. No other product or vendor information is provided.
Risk and Exploitability
The EPSS score is < 1%, and the CVSS score is 9.1, indicating a critical severity. The vulnerability is not listed in CISA KEV. The SSRF flaw allows an attacker to direct the JetLinks server to request arbitrary internal or external URLs, potentially revealing sensitive data or enabling further exploitation. Access appears to require the ability to reach the import endpoint, suggesting a local or network‑level attack vector that needs a valid session or network access to the JetLinks server.
OpenCVE Enrichment