CVE-2026-2563: medium-severity vulnerability in JingDong JD Cloud Box AX6600
JingDong JD Cloud Box AX6600 jdcapp_rpc controlDevice get_status privileges management
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.6%
exploitation probability
0.6%top 52% of all CVEs
observed exploitation
nono source reports it
A vulnerability was identified in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. Affected is the function set_stcreenen_deabled_status/get_status of the file /f/service/controlDevice of the component jdcapp_rpc. The manipulation leads to Remote Privilege Escalation. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
JingDong · JD Cloud Box AX6600Related CVEs — JingDong JD Cloud Box AX6600
In the same product, most dangerous first.
CVE-2026-2562MEDIUMJingDong JD Cloud Box AX6600 jdcweb_rpc jdcapi cast_streen privileges managementEPSS 0.6%CVE-2026-2561MEDIUMJingDong JD Cloud Box AX6600 jdcweb_rpc jdcapi web_get_ddns_uptime privileges managementEPSS 0.6%CVE-2026-11413HIGHJingDong JD Cloud Box AX6600 jdcweb_rpc set_macfilter stack-based overflowEPSS 0.5%