Path Traversal Vulnerability in AJCloud AJY IPC Firmware
A path traversal vulnerability in the AJCloud AJY IPC jdbhttpd web service allows unauthenticated remote attackers to read arbitrary files with root privileges via crafted URI requests.
CVE search metadata
CVE search record: CVE-2026-56718. Severity: high. CVSS: 7.5. KEV: no. Product: AJY IPC firmware (< 01.10715.11.37). Brief: Path Traversal Vulnerability in AJCloud AJY IPC Firmware. Brief link: https://feed.craftedsignal.io/briefs/2026-08-ajcloud-path-traversal/
AJCloud AJY IPC firmware versions prior to 01.10715.11.37 contain a path traversal vulnerability in the jdbhttpd web service. This flaw enables unauthenticated remote attackers to bypass access controls and read arbitrary files on the underlying file system with root privileges. By injecting path traversal sequences into HTTP requests directed at port 80, an adversary can retrieve sensitive system files. The exposure includes credentials for RTSP streams, Wi-Fi network SSID and pre-shared keys, device serial numbers, and cloud binding parameters. This vulnerability represents a significant risk for the confidentiality of device configurations and network access credentials, potentially facilitating lateral movement or further exploitation within the connected environment.
Impact
Successful exploitation allows for the unauthorized extraction of sensitive configuration data, including Wi-Fi security keys and RTSP credentials. These data points provide an attacker with the ability to gain network access or intercept video streams from the affected cameras. The scope of targeting includes all deployments of AJY IPC devices running firmware versions earlier than 01.10715.11.37.
Recommendation
Update the firmware for all AJCloud AJY IPC devices to version 01.10715.11.37 or later immediately to address CVE-2026-56718. For environments where patching cannot occur immediately, restrict access to the web management interface on port 80 to trusted management subnets using network segmentation or firewall ACLs.
Immediate actions
Upgrade AJY IPC firmware to 01.10715.11.37 or later.
Mitigations
Restrict access to port 80 on AJCloud devices via firewall ACLs.
CVE-2026-56718
Detection coverage 1
Detects CVE-2026-56718 Exploitation - Path Traversal in AJCloud jdbhttpd
highDetects attempts to exploit CVE-2026-56718 by identifying path traversal sequences (../) in HTTP requests targeting AJCloud IPC devices
Detection queries are available on the platform. Get full rules →