A vulnerability was found in Intelbras VIP 3260 Z IA 2.840.00IB005.0.T. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /OutsideCmd. The manipulation results in weak password recovery.
This vulnerability is known as CVE-2026-2564. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability was found in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533. It has been classified as critical. Affected is the function set_stcreenen_deabled_status/get_status of the file /f/service/controlDevice of the component jdcapp_rpc. The manipulation leads to privilege escalation.
This vulnerability is traded as CVE-2026-2563. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533 and classified as critical. This impacts the function cast_streen of the file /jdcapi of the component jdcweb_rpc. Executing a manipulation of the argument File can lead to privilege escalation.
This vulnerability appears as CVE-2026-2562. The attack may be performed from remote. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability has been found in JingDong JD Cloud Box AX6600 up to 4.5.1.r4533 and classified as critical. This affects the function web_get_ddns_uptime of the file /jdcapi of the component jdcweb_rpc. Performing a manipulation results in privilege escalation.
This vulnerability is reported as CVE-2026-2561. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability, which was classified as critical, was found in kalcaddle kodbox up to 1.64.05. The impacted element is the function run of the file plugins/fileThumb/lib/VideoResize.class.php of the component Media File Preview Plugin. Such manipulation of the argument localFile leads to os command injection.
This vulnerability is documented as CVE-2026-2560. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.