CVE-2025-66848Disclosure(jdcloud / ax1800)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

JD Cloud NAS routers AX1800 (4.3.1.r4308 and earlier), AX3000 (4.3.1.r4318 and earlier), AX6600 (4.5.1.r4533 and earlier), BE6500 (4.4.1.r4308 and earlier), ER1 (4.5.1.r4518 and earlier), and ER2 (4.5.1.r4518 and earlier) contain an unauthorized remote command execution vulnerability.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ax1800
  • ax1800_firmware
  • ax3000
  • ax3000_firmware

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ax1800ax1800_firmwareax3000ax3000_firmwareax6600ax6600_firmwarebe6500be6500_firmwareer1er1_firmware

1 version affected across 12 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-06: 1Technical Details · 2026-02-06: 102-06
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Komodo Cyber Security@Komodosec
    Disclosure

    #VulnerabilityReport #AuthenticationBypass CVE-2025-66848: Critical Flaw in JD Cloud Routers Grants Hackers Root Access https://securityonline.info/cve-2025-66848-critical-flaw-in-jd-cloud-routers-grants-hackers-root-access/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet announces the discovery of a critical authentication bypass in JD Cloud routers that allows attackers to gain root access, constituting a vulnerability disclosure.

    1000071
    1.5K followersView on X
CPE platform detail12 entries

12 of 12 entries

PartVendorProductVersionTarget SWTarget HW
HWjdcloudax1800---
OSjdcloudax1800_firmware---
HWjdcloudax3000---
OSjdcloudax3000_firmware---
HWjdcloudax6600---
OSjdcloudax6600_firmware---
HWjdcloudbe6500---
OSjdcloudbe6500_firmware---
HWjdclouder1---
OSjdclouder1_firmware---
HWjdclouder2---
OSjdclouder2_firmware---

Explore more