Incibe • 9w
Critical Buffer Overflow Vulnerability in JingDong JD Cloud Box AX6600
A critical buffer overflow vulnerability, designated as CVE-2026-11413, has been identified in the JingDong JD Cloud Box AX6600. This vulnerability allows an attacker to trigger memory corruption (CWE-121/CWE-122) within specific firmware processes, potentially resulting in unauthenticated Remote Code Execution (RCE) or a complete Denial of Service (DoS). Due to the hardware's function as a cloud-integrated gateway, successful exploitation allows an adversary to intercept local network traffic, establish persistent access, and facilitate lateral movement into protected internal environments. Security professionals should prioritize identifying these devices within their network architecture to prevent unauthorized pivoting.