CVE-2026-47097 PUBLISHED

AJA HELO Plus < 2.1.7 Static AES Passphrase Information Disclosure via /diags

Assigner: VulnCheck
Reserved: 18.05.2026 Published: 30.09.2026 Updated: 30.09.2026

AJA HELO Plus firmware before 2.1.7 contains an information disclosure vulnerability that allows unauthenticated attackers to decrypt sensitive diagnostics bundles by exploiting a static AES passphrase embedded in obfuscated form within the firmware. Attackers can reverse engineer the publicly available firmware image to recover the shared passphrase and decrypt diagnostics export bundles retrieved from the unauthenticated diagnostics endpoint on any affected device, exposing highly sensitive server information.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor AJA Video Systems
Product HELO Plus
Versions Default: unaffected
  • affected from 0 to 2.1.7 (excl.)

Credits

  • Saleh Alghamdi finder
  • Abdulrahman Aldossary finder

References

Problem Types

  • Use of Hard-coded Cryptographic Key CWE