Jdcloud's vulnerability footprint centers on a modestly represented line of wireless networking and IoT devices, including routers and mesh systems such as the AX6600, AX1800, and AX3000 product families. The recurring signal clusters around privilege-management and code-injection weaknesses, reflecting the access-control and input-handling demands of embedded network firmware. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jdcloud over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-66848CRITICAL JD Cloud NAS routers AX1800 (4.3.1.r4308 and earlier), AX3000 (4.3.1.r4318 and earlier), AX6600 (4.5.1.r4533 and earlier), BE6500 (4.4.1.r4308 and earlier), ER1 (4.5.1.r4518 and ea | Dec 30, 2025 | 9.8 | 34 | NO | NO |
CVE-2026-2562HIGH A vulnerability was determined in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. This impacts the function cast_streen of the file /jdcapi of the component jdcweb_rpc. Executing a | Feb 16, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-2563HIGH A vulnerability was identified in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. Affected is the function set_stcreenen_deabled_status/get_status of the file /f/service/controlDev | Feb 16, 2026 | 8.8 | 25 | NO | NO |
CVE-2026-2561HIGH A vulnerability was found in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. This affects the function web_get_ddns_uptime of the file /jdcapi of the component jdcweb_rpc. Performi | Feb 16, 2026 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jdcloud.
Media articles that mention a CVE ID that affects a product developed by Jdcloud — matched by CVE ID, not by vendor name.