CVE-2025-66848

CRITICAL

JD Cloud NAS Routers - Unauthorized Remote Command Execution

Title source: manual
STIX 2.1

Description

JD Cloud NAS routers AX1800 (4.3.1.r4308 and earlier), AX3000 (4.3.1.r4318 and earlier), AX6600 (4.5.1.r4533 and earlier), BE6500 (4.4.1.r4308 and earlier), ER1 (4.5.1.r4518 and earlier), and ER2 (4.5.1.r4518 and earlier) contain an unauthorized remote command execution vulnerability.

References (3)

Core 3

Scores

CVSS v3 9.8
EPSS 0.0101
EPSS Percentile 58.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Products (6)
jdcloud/ax1800_firmware < 4.3.1.r4308
jdcloud/ax3000_firmware < 4.3.1.r4318
jdcloud/ax6600_firmware < 4.5.1.r4533
jdcloud/be6500_firmware < 4.4.1.r4308
jdcloud/er1_firmware < 4.5.1.r4518
jdcloud/er2_firmware < 4.5.1.r4518
Published Dec 30, 2025
Tracked Since Feb 18, 2026