← All CVEs

CVE-2025-66848

critical · 9.8

JD Cloud NAS routers AX1800 (4.3.1.r4308 and earlier), AX3000 (4.3.1.r4318 and earlier), AX6600 (4.5.1.r4533 and earlier), BE6500 (4.4.1.r4308 and earlier), ER1 (4.5.1.r4518 and earlier), and ER2 (4.5.1.r4518 and earlier) contain an unauthorized remote command execution vulnerability.

9.8
CVSS
1.0%
EPSS (exploit prob.)
62nd
EPSS percentile
2025-12-30
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-94

Affected products

VendorProductAffected versions
jdcloudax1800_firmware<= 4.3.1.r4308
jdcloudax1800all versions
jdcloudax3000_firmware<= 4.3.1.r4318
jdcloudax3000all versions
jdcloudax6600_firmware<= 4.5.1.r4533
jdcloudax6600all versions
jdcloudbe6500_firmware<= 4.4.1.r4308
jdcloudbe6500all versions
jdclouder1_firmware<= 4.5.1.r4518
jdclouder1all versions
jdclouder2_firmware<= 4.5.1.r4518
jdclouder2all versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-66848