CVE-2025-66848
JD Cloud NAS routers AX1800 (4.3.1.r4308 and earlier), AX3000 (4.3.1.r4318 and earlier), AX6600 (4.5.1.r4533 and earlier), BE6500 (4.4.1.r4308 and earlier), ER1 (4.5.1.r4518 and earlier), and ER2 (4.5.1.r4518 and earlier) contain an unauthorized remote command execution vulnerability.
Published:Dec 30, 2025
Last Modified:Jan 9, 2026
EPS:Dec 30, 2025
EPSS Score:0.00405
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Jdcloud
Product
Ax1800
Jdcloud
Ax1800
Vendor
Jdcloud
Product
Ax1800 Firmware
Jdcloud
Ax1800 Firmware
Vendor
Jdcloud
Product
Ax3000
Jdcloud
Ax3000
Vendor
Jdcloud
Product
Ax3000 Firmware
Jdcloud
Ax3000 Firmware
Vendor
Jdcloud
Product
Ax6600
Jdcloud
Ax6600
Vendor
Jdcloud
Product
Ax6600 Firmware
Jdcloud
Ax6600 Firmware
Vendor
Jdcloud
Product
Be6500
Jdcloud
Be6500
Vendor
Jdcloud
Product
Be6500 Firmware
Jdcloud
Be6500 Firmware
Vendor
Jdcloud
Product
Er1
Jdcloud
Er1
Vendor
Jdcloud
Product
Er1 Firmware
Jdcloud
Er1 Firmware
Vendor
Jdcloud
Product
Er2
Jdcloud
Er2
Vendor
Jdcloud
Product
Er2 Firmware
Jdcloud
Er2 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
