<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:o:ajcloud:ajy_ipc_firmware:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3oajcloudajy_ipc_firmware/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 30 Aug 2026 23:12:41 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3oajcloudajy_ipc_firmware/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Path Traversal Vulnerability in AJCloud AJY IPC Firmware</title><link>https://feed.craftedsignal.io/briefs/2026-08-ajcloud-path-traversal/</link><pubDate>Sun, 30 Aug 2026 23:12:41 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-ajcloud-path-traversal/</guid><description>A path traversal vulnerability in the AJCloud AJY IPC jdbhttpd web service allows unauthenticated remote attackers to read arbitrary files with root privileges via crafted URI requests.</description><content:encoded><![CDATA[<p>AJCloud AJY IPC firmware versions prior to 01.10715.11.37 contain a path traversal vulnerability in the jdbhttpd web service. This flaw enables unauthenticated remote attackers to bypass access controls and read arbitrary files on the underlying file system with root privileges. By injecting path traversal sequences into HTTP requests directed at port 80, an adversary can retrieve sensitive system files. The exposure includes credentials for RTSP streams, Wi-Fi network SSID and pre-shared keys, device serial numbers, and cloud binding parameters. This vulnerability represents a significant risk for the confidentiality of device configurations and network access credentials, potentially facilitating lateral movement or further exploitation within the connected environment.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the unauthorized extraction of sensitive configuration data, including Wi-Fi security keys and RTSP credentials. These data points provide an attacker with the ability to gain network access or intercept video streams from the affected cameras. The scope of targeting includes all deployments of AJY IPC devices running firmware versions earlier than 01.10715.11.37.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the firmware for all AJCloud AJY IPC devices to version 01.10715.11.37 or later immediately to address CVE-2026-56718. For environments where patching cannot occur immediately, restrict access to the web management interface on port 80 to trusted management subnets using network segmentation or firewall ACLs.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>path-traversal</category><category>iiot</category><category>cve-2026-56718</category></item></channel></rss>