CVE-2026-47097
Received Received - Intake

AJAX HELO Plus Firmware Information Disclosure

Vulnerability report for CVE-2026-47097, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulnCheck

Description

AJA HELO Plus firmware before 2.1.7 contains an information disclosure vulnerability that allows unauthenticated attackers to decrypt sensitive diagnostics bundles by exploiting a static AES passphrase embedded in obfuscated form within the firmware. Attackers can reverse engineer the publicly available firmware image to recover the shared passphrase and decrypt diagnostics export bundles retrieved from the unauthenticated diagnostics endpoint on any affected device, exposing highly sensitive server information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
aja_video_systems helo_plus to 2.1.7 (exc)
aja helo_plus_firmware to 2.1.7 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-321 The product uses a hard-coded, unchangeable cryptographic key.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-47097 is an information disclosure vulnerability in AJA HELO Plus firmware before version 2.1.7. It involves a static AES passphrase embedded in the firmware that allows unauthenticated attackers to decrypt sensitive diagnostics bundles. Attackers can reverse engineer the firmware to recover the passphrase and decrypt data from the unauthenticated diagnostics endpoint on affected devices.

Detection Guidance

Check if your AJA HELO Plus firmware version is below 2.1.7 by accessing the device's web interface or using network scanning tools. Inspect diagnostics bundles downloaded from the unauthenticated diagnostics endpoint for signs of decryption failures or unusual data exposure. Review network traffic for unauthorized access attempts to the diagnostics endpoint.

Impact Analysis

This vulnerability allows attackers to access highly sensitive server information by decrypting diagnostics bundles. Since the passphrase is static and embedded in the firmware, any device running affected versions is at risk of unauthorized data exposure without authentication.

Compliance Impact

This vulnerability could potentially violate compliance with GDPR and HIPAA due to the exposure of highly sensitive server information through decrypted diagnostics bundles. Unauthorized access to such data may lead to breaches of confidentiality requirements under these regulations.

Mitigation Strategies

Update the AJA HELO Plus firmware to version 2.1.7 or later immediately. Disable or restrict access to the unauthenticated diagnostics endpoint if possible. Ensure no sensitive diagnostics bundles have been accessed or decrypted by unauthorized parties. Monitor network traffic for suspicious activity related to this device.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47097. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart