JD Cloud JDCOS Command Injection Vulnerability in Service Interface Component

Vulnerability

A command injection vulnerability has been identified in JD Cloud JDCOS version 4.5.1.r4518. The issue arises in the Service Interface component, specifically within the set_iptv_info function of the jdcap file. The vulnerability can be exploited remotely by manipulating the vid argument.

Impact

Exploitation of this vulnerability allows for command injection, where an attacker can execute arbitrary commands on the server.

Added: May 3, 2026, 11:20 PM
Updated: May 3, 2026, 11:20 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.7
remediation
0.0
relevance
7.3
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.