CVE-2026-47097
AJA HELO Plus < 2.1.7 Static AES Passphrase Information Disclosure via /diags
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
AJA HELO Plus firmware before 2.1.7 contains an information disclosure vulnerability that allows unauthenticated attackers to decrypt sensitive diagnostics bundles by exploiting a static AES passphrase embedded in obfuscated form within the firmware. Attackers can reverse engineer the publicly available firmware image to recover the shared passphrase and decrypt diagnostics export bundles retrieved from the unauthenticated diagnostics endpoint on any affected device, exposing highly sensitive server information.
| CWE | CWE-321 |
| Vendor | aja video systems |
| Product | helo plus |
| Published | Sep 30, 2026 |
| Last Updated | Sep 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for aja video systems helo plus
Be the first to know when new high vulnerabilities affecting aja video systems helo plus are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
AJA Video Systems / HELO Plus
0 < 2.1.7
References
Credits
Saleh Alghamdi Abdulrahman Aldossary