CVE-2025-66848 Details
Description
JD Cloud NAS routers AX1800 (4.3.1.r4308 and earlier), AX3000 (4.3.1.r4318 and earlier), AX6600 (4.5.1.r4533 and earlier), BE6500 (4.4.1.r4308 and earlier), ER1 (4.5.1.r4518 and earlier), and ER2 (4.5.1.r4518 and earlier) contain an unauthorized remote command execution vulnerability.
A vulnerability allowing unauthorized remote command execution has been identified in several models of JD Cloud NAS routers, including the AX1800, AX3000, AX6600, BE6500, ER1, and ER2. The vulnerability exists in specific firmware versions, with each model having its own version range that is affected. The root cause of this vulnerability is not specified.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.notion.so/JD-Cloud-Unauth-RCE-2d22b76e8e0c802c975bf186b208d0c2 | [email protected] | Permissions Required |
| https://www.jdcloud.com/cn/ | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| jdcloud ax1800 firmware | <= 4.3.1.r4308 |
CPE
Remediation
| |
| jdcloud ax1800 | All versions |
CPE
Remediation
| |
| jdcloud ax3000 firmware | <= 4.3.1.r4318 |
CPE
Remediation
| |
| jdcloud ax3000 | All versions |
CPE
Remediation
| |
| jdcloud ax6600 firmware | <= 4.5.1.r4533 |
CPE
Remediation
| |
| jdcloud ax6600 | All versions |
CPE
Remediation
| |
| jdcloud be6500 firmware | <= 4.4.1.r4308 |
CPE
Remediation
| |
| jdcloud be6500 | All versions |
CPE
Remediation
| |
| jdcloud er1 firmware | <= 4.5.1.r4518 |
CPE
Remediation
| |
| jdcloud er1 | All versions |
CPE
Remediation
| |
| jdcloud er2 firmware | <= 4.5.1.r4518 |
CPE
Remediation
| |
| jdcloud er2 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 9, 2026 | Initial Analysis | [email protected] |
| Jan 2, 2026 | CVE Modified | CISA-ADP |
| Dec 30, 2025 | New CVE Received | [email protected] |