PatchSiren

JetLinks CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL JetLinks CVE published 2026-08-26

CVE-2026-75340

A Server-side request forgery (SSRF) vulnerability exists in the device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11. This critical vulnerability has a CVSS score of 9.1. The vulnerability allows an attacker to make unauthorized requests on behalf of the server, potentially leading to sensitive information disclosure or further exploitation. De [truncated]