AJA HELO Plus < 2.1.7 Hardcoded AES Passphrase for Diagnostics Export Bundle
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.7epss 0.4%
exploitation probability
0.4%top 70% of all CVEs
observed exploitation
nono source reports it
AJA HELO Plus firmware before 2.1.7 contains an information disclosure vulnerability that allows unauthenticated attackers to decrypt sensitive diagnostics bundles by exploiting a static AES passphrase embedded in obfuscated form within the firmware. Attackers can reverse engineer the publicly available firmware image to recover the shared passphrase and decrypt diagnostics export bundles retrieved from the unauthenticated diagnostics endpoint on any affected device, exposing highly sensitive server information.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
AJA Video Systems · HELO PlusReferences
https://d26ddnfpy9hzf8.cloudfront.net/aja-web/public/pdf/2026/AJA_HELO_PLUS_ReleaseNotes_v2.1.7.pdfhttps://www.aja.com/security-advisories/aja-sa-2026-003https://www.aja.com/support/item/10457https://www.vulncheck.com/advisories/aja-helo-plus-hardcoded-aes-passphrase-for-diagnostics-export-bundle