← Back

CVE-2025-66848

nvd nist
Published: Dec 30, 2025Modified: Jan 9, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

JD Cloud NAS routers AX1800 (4.3.1.r4308 and earlier), AX3000 (4.3.1.r4318 and earlier), AX6600 (4.5.1.r4533 and earlier), BE6500 (4.4.1.r4308 and earlier), ER1 (4.5.1.r4518 and earlier), and ER2 (4.5.1.r4518 and earlier) contain an unauthorized remote command execution vulnerability.

Affected (6)

6 products
Ax1800 Firmware
Ax3000 Firmware
Ax6600 Firmware
Be6500 Firmware
Er1 Firmware
Er2 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 4.3.1.r4308
Running on/withPlatform Versions
Jdcloud
Ax1800
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 4.3.1.r4318
Running on/withPlatform Versions
Jdcloud
Ax3000
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 4.5.1.r4533
Running on/withPlatform Versions
Jdcloud
Ax6600
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 4.4.1.r4308
Running on/withPlatform Versions
Jdcloud
Be6500
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 4.5.1.r4518
Running on/withPlatform Versions
Jdcloud
Er1
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 4.5.1.r4518
Running on/withPlatform Versions
Jdcloud
Er2
All versions

References (3)

Source: cve@mitre.org
Not Applicable
Source: nvd@nist.gov
Product

Timeline

No history available yet.