Medium severity6.3NVD Advisory· Published Feb 16, 2026· Updated Apr 29, 2026
CVE-2026-2563
CVE-2026-2563
Description
A vulnerability was identified in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. Affected is the function set_stcreenen_deabled_status/get_status of the file /f/service/controlDevice of the component jdcapp_rpc. The manipulation leads to Remote Privilege Escalation. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
2- Range: <=4.5.1.r4533
Patches
Vulnerability mechanics
References
5- my.feishu.cn/wiki/T3pjwxZtYiU4Gfkl6iUc3CzVnRenvdPermissions RequiredThird Party Advisory
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.