PT-2026-36722 · Jd Cloud · Jdcos

2Er00Ne

·

Published

2026-05-03

·

Updated

2026-05-04

·

CVE-2026-7705

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions JD Cloud JDCOS version 4.5.1.r4518
Description A flaw in the Service Interface component allows remote command injection. The issue exists within the set iptv info() function of the '/jdcap' file, where improper handling of the vid argument enables the execution of arbitrary commands.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the '/jdcap' file or disable the set iptv info() function to minimize the risk of exploitation.

Exploit

Command Injection

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-7705

Affected Products

Jdcos