CVE-2025-66848
Last modified
CVE-2025-66848 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. JD Cloud NAS routers AX1800 (4.3.1.r4308 and earlier), AX3000 (4.3.1.r4318 and earlier), AX6600 (4.5.1.r4533 and earlier), BE6500 (4.4.1.r4308 and earlier), ER1 (4.5.1.r4518 and earlier), and ER2 (4.5.1.r4518 and earlier) contain an unauthorized remote command execution vulnerability.. EPSS estimates a 1.01% chance of exploitation in the next 30 days.
Description
JD Cloud NAS routers AX1800 (4.3.1.r4308 and earlier), AX3000 (4.3.1.r4318 and earlier), AX6600 (4.5.1.r4533 and earlier), BE6500 (4.4.1.r4308 and earlier), ER1 (4.5.1.r4518 and earlier), and ER2 (4.5.1.r4518 and earlier) contain an unauthorized remote command execution vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jdcloud | Ax1800 Firmware | <= 4.3.1.r4308 |
| Jdcloud | Ax3000 Firmware | <= 4.3.1.r4318 |
| Jdcloud | Ax6600 Firmware | <= 4.5.1.r4533 |
| Jdcloud | Be6500 Firmware | <= 4.4.1.r4308 |
| Jdcloud | Er1 Firmware | <= 4.5.1.r4518 |
| Jdcloud | Er2 Firmware | <= 4.5.1.r4518 |
References
- http://jd.comNot Applicable
- https://www.notion.so/JD-Cloud-Unauth-RCE-2d22b76e8e0c802c975bf186b208d0c2Permissions Required
- https://www.jdcloud.com/cn/Product
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-66848?
How severe is CVE-2025-66848?
How do I fix CVE-2025-66848?
Are you affected by CVE-2025-66848?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
