---
id: CVE-2026-56718
title: >-
  AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path
  traversal vulnerability in the jdbhttpd web service that allows
  unauthenticated remote attackers to read arbitrary files with root privileges
  by supplying path trav…
summary: >-
  AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path
  traversal vulnerability in the jdbhttpd web service that allows
  unauthenticated remote attackers to read arbitrary files with root privileges
  by supplying path trav…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-22
published: '2026-08-30'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:53:23.707'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-56718'
references:
  - url: 'https://hellkid.dev/writeups/cve-2026-56718/'
    label: disclosure@vulncheck.com
  - url: 'https://www.ajcloud.net/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/ajcloud-ajy-ipc-firmware-path-traversal-via-jdbhttpd
    label: disclosure@vulncheck.com
tags:
  - nvd
  - exploit-available
epss: 0.00944
epssPercentile: 0.59416
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/hellkkid/CVE-2026-56718'
  checkedAt: '2026-09-26T09:05:50.927Z'
exploitAvailable: true
ingestedAt: '2026-09-10T16:57:28.692Z'
---

## Overview

AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by supplying path traversal sequences in the HTTP request URI. Attackers can send crafted HTTP requests to port 80 without authentication to access sensitive files including cleartext RTSP credentials, Wi-Fi SSID and pre-shared key, device serial number, and cloud binding parameters.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
