CVE-2026-58452 Details
Description
JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by supplying a malicious Wireless parameter to the HTTP PUT NetSDK/Factory SetMAC endpoint. Attackers can craft a string beginning with a valid MAC-like prefix followed by a semicolon and a shell payload, which bypasses partial sscanf() validation and is passed unsanitized into an echo shell command executed through a system() wrapper.
An OS command injection vulnerability has been identified in JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411. This vulnerability allows authenticated attackers to execute remote code by sending a malicious Wireless parameter to the HTTP PUT NetSDK/Factory SetMAC endpoint. The exploitation involves crafting a string that begins with a valid MAC-like prefix, followed by a semicolon and a shell payload. This crafted string bypasses partial validation by sscanf() and is passed unsanitized into an echo command, which is executed via a system() wrapper.
Users are advised to update to the latest firmware version that addresses this vulnerability. Check the JAIOTlink official website or contact their support for information on available updates.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 1, 2026CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| JAIOTlink C492A-W6 | <= 4.8.30.57701411 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jul 1, 2026 | New CVE Received | [email protected] |
Volerion