Ajcloud · Ajy Ipc · CVE-2026-56718
**Name of the Vulnerable Software and Affected Versions**
AJCloud AJY IPC versions prior to 01.10715.11.37
**Description**
The `jdbhttpd` web service contains a path traversal flaw that allows unauthenticated remote attackers to read arbitrary files with root privileges. By sending crafted HTTP requests to port 80 and including path traversal sequences in the request URI, an attacker can access sensitive information such as cleartext RTSP credentials, Wi-Fi SSID and pre-shared keys, device serial numbers, and cloud binding parameters.
**Recommendations**
Update AJCloud AJY IPC to version 01.10715.11.37 or later.