PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-75340 JetLinks CVE debrief

A Server-side request forgery (SSRF) vulnerability exists in the device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11. This critical vulnerability has a CVSS score of 9.1. The vulnerability allows an attacker to make unauthorized requests on behalf of the server, potentially leading to sensitive information disclosure or further exploitation. Defenders should assess exposure and prioritize remediation of this critical SSRF vulnerability.

Vendor
JetLinks
Product
JetLinks Community 2.11
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-26
Original CVE updated
2026-09-09
Advisory published
2026-08-26
Advisory updated
2026-09-09

Who should care

Defenders responsible for systems using jetlinks community 2.11, especially those using the device metadata import interface, should assess exposure and prioritize remediation of this critical SSRF vulnerability.

Why it matters

A critical SSRF vulnerability exists in jetlinks community 2.11, requiring verification of exposure and remediation to prevent potential attacks.

  • Verification of exposure to the device metadata import interface /device/instance/{productId}/property-metadata/import is required to determine potential impact.
  • Remediation of the SSRF vulnerability is necessary to prevent potential attacks.
  • Defenders should assess the impact of the vulnerability on systems using jetlinks community 2.11.

Technical summary

The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF). This critical vulnerability has a CVSS score of 9.1. The vulnerability allows an attacker to make unauthorized requests on behalf of the server, potentially leading to sensitive information disclosure or further exploitation. The affected product is jetlinks community 2.11, and defenders should verify exposure to the device metadata import interface.

Defensive priority

Defenders should prioritize verification of exposure and remediation of this critical SSRF vulnerability in jetlinks community 2.11, especially for systems using the device metadata import interface.

Recommended defensive actions

  • Verify exposure to the device metadata import interface /device/instance/{productId}/property-metadata/import
  • Assess the impact of the SSRF vulnerability on systems using jetlinks community 2.11
  • Remediate the vulnerability by applying the necessary patches or mitigations

Evidence notes

The CVE record and NVD entry provide limited information about the vulnerability. Further verification is required to determine the affected versions, exploitation, and remediation.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-75340 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-75340

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-75340 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-75340

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.