PT-2026-36722 · Jd Cloud · Jdcos
2Er00Ne
·
Published
2026-05-03
·
Updated
2026-05-04
·
CVE-2026-7705
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
JD Cloud JDCOS version 4.5.1.r4518
Description
A flaw in the Service Interface component allows remote command injection. The issue exists within the
set iptv info() function of the '/jdcap' file, where improper handling of the vid argument enables the execution of arbitrary commands.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict access to the '/jdcap' file or disable the
set iptv info() function to minimize the risk of exploitation.Exploit
Command Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Jdcos