CVE-2025-66848

EUVD-2025-205835
JD Cloud NAS routers AX1800 (4.3.1.r4308 and earlier), AX3000 (4.3.1.r4318 and earlier), AX6600 (4.5.1.r4533 and earlier), BE6500 (4.4.1.r4308 and earlier), ER1 (4.5.1.r4518 and earlier), and ER2 (4.5.1.r4518 and earlier) contain an unauthorized remote command execution vulnerability.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 62%
Affected Products (NVD)
VendorProductVersion
jdcloudax1800_firmware
𝑥
≤ 4.3.1.r4308
jdcloudax3000_firmware
𝑥
≤ 4.3.1.r4318
jdcloudax6600_firmware
𝑥
≤ 4.5.1.r4533
jdcloudbe6500_firmware
𝑥
≤ 4.4.1.r4308
jdclouder1_firmware
𝑥
≤ 4.5.1.r4518
jdclouder2_firmware
𝑥
≤ 4.5.1.r4518
𝑥
= Vulnerable software versions