{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-56718/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:ajcloud:ajy_ipc_firmware:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-56718"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AJY IPC firmware (\u003c 01.10715.11.37)"],"_cs_severities":["high"],"_cs_tags":["path-traversal","iiot","cve-2026-56718"],"_cs_type":"advisory","_cs_vendors":["AJCloud"],"content_html":"\u003cp\u003eAJCloud AJY IPC firmware versions prior to 01.10715.11.37 contain a path traversal vulnerability in the jdbhttpd web service. This flaw enables unauthenticated remote attackers to bypass access controls and read arbitrary files on the underlying file system with root privileges. By injecting path traversal sequences into HTTP requests directed at port 80, an adversary can retrieve sensitive system files. The exposure includes credentials for RTSP streams, Wi-Fi network SSID and pre-shared keys, device serial numbers, and cloud binding parameters. This vulnerability represents a significant risk for the confidentiality of device configurations and network access credentials, potentially facilitating lateral movement or further exploitation within the connected environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the unauthorized extraction of sensitive configuration data, including Wi-Fi security keys and RTSP credentials. These data points provide an attacker with the ability to gain network access or intercept video streams from the affected cameras. The scope of targeting includes all deployments of AJY IPC devices running firmware versions earlier than 01.10715.11.37.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the firmware for all AJCloud AJY IPC devices to version 01.10715.11.37 or later immediately to address CVE-2026-56718. For environments where patching cannot occur immediately, restrict access to the web management interface on port 80 to trusted management subnets using network segmentation or firewall ACLs.\u003c/p\u003e\n","date_modified":"2026-08-30T23:12:41Z","date_published":"2026-08-30T23:12:41Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ajcloud-path-traversal/","summary":"A path traversal vulnerability in the AJCloud AJY IPC jdbhttpd web service allows unauthenticated remote attackers to read arbitrary files with root privileges via crafted URI requests.","title":"Path Traversal Vulnerability in AJCloud AJY IPC Firmware","url":"https://feed.craftedsignal.io/briefs/2026-08-ajcloud-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-56718","version":"https://jsonfeed.org/version/1.1"}