CVE-2026-2561 | JingDong JD Cloud Box AX6600 up to 4.5.1.r4533 jdcweb_rpc /jdcapi web_get_ddns_uptime privileges management (EUVD-2026-6082)
A vulnerability has been found in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533 and classified as critical. This affects the function web_get_ddns_uptime of the file /jdcapi of the component jdcweb_rpc. Performing a manipulation results in improper privilege management.
This vulnerability is reported as CVE-2026-2561. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.