PatchSiren cyber security CVE debrief
CVE-2026-75340 JetLinks CVE debrief
A Server-side request forgery (SSRF) vulnerability exists in the device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11. This critical vulnerability has a CVSS score of 9.1. The vulnerability allows an attacker to make unauthorized requests on behalf of the server, potentially leading to sensitive information disclosure or further exploitation. Defenders should assess exposure and prioritize remediation of this critical SSRF vulnerability.
- Vendor
- JetLinks
- Product
- JetLinks Community 2.11
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-26
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-26
- Advisory updated
- 2026-09-09
Who should care
Defenders responsible for systems using jetlinks community 2.11, especially those using the device metadata import interface, should assess exposure and prioritize remediation of this critical SSRF vulnerability.
Why it matters
A critical SSRF vulnerability exists in jetlinks community 2.11, requiring verification of exposure and remediation to prevent potential attacks.
- Verification of exposure to the device metadata import interface /device/instance/{productId}/property-metadata/import is required to determine potential impact.
- Remediation of the SSRF vulnerability is necessary to prevent potential attacks.
- Defenders should assess the impact of the vulnerability on systems using jetlinks community 2.11.
Technical summary
The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF). This critical vulnerability has a CVSS score of 9.1. The vulnerability allows an attacker to make unauthorized requests on behalf of the server, potentially leading to sensitive information disclosure or further exploitation. The affected product is jetlinks community 2.11, and defenders should verify exposure to the device metadata import interface.
Defensive priority
Defenders should prioritize verification of exposure and remediation of this critical SSRF vulnerability in jetlinks community 2.11, especially for systems using the device metadata import interface.
Recommended defensive actions
- Verify exposure to the device metadata import interface /device/instance/{productId}/property-metadata/import
- Assess the impact of the SSRF vulnerability on systems using jetlinks community 2.11
- Remediate the vulnerability by applying the necessary patches or mitigations
Evidence notes
The CVE record and NVD entry provide limited information about the vulnerability. Further verification is required to determine the affected versions, exploitation, and remediation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-75340 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-75340
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-75340 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75340
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/fangtang7/CVE/blob/main/jetlinks-community/ssrf.md
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.