Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-56718 — AJCloud AJY IPC Firmware Path Traversal via jdbhttpd | Kitploit
Tools/GitHubGitHub/hellkkid/cve-2026-56718
Embedded Systems SecurityReconnaissanceIoT SecurityVulnerability AnalysisExploitationWeb Application Exploitation
GitHubhellkkid/cve-2026-56718

CVE-2026-56718

AJCloud AJY IPC Firmware Path Traversal via jdbhttpd

View Repository
1821 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-56718

Unauthenticated path traversal in jdbhttpd/0.1.0 (AJCloud AJY IPC firmware) allowing remote reading of arbitrary files as root, including cleartext RTSP credentials.

  • CWE: CWE-22 (Improper Limitation of a Pathname to a Restricted Directory)
  • Severity: CVSS 4.0 - 8.7 (High)
  • Affected: AJCloud AJY IPC Firmware < 01.10715.11.37
  • Credits: Alessandro Ciotti (finder), VulnCheck (coordinator)

Summary

jdbhttpd resolves files from the request URI without preventing ../ traversal outside the web root. An unauthenticated attacker on the network can read arbitrary files as root, recover the stored RTSP credentials, and use them to access the video stream.

Full writeup

Full analysis: CVE-2026-56718

References

  • MITRE CVE record
  • VulnCheck advisory
Download Tool