CVE-2026-52482 Details
Description
An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the inetd service spawns /app/sh_for_telnet
A vulnerability in the SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows remote access to a root shell through Telnet on port 23. The issue arises because the inetd service spawns a binary that executes a shell as root without any authentication. This vulnerability is exploitable over the drone's open WiFi network, which lacks encryption or password protection.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 9, 2026CISA-ADP
Assessed Sep 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/AshtonKopelevich/SJ-GPS-PRO-F11-Vulnerability | [email protected] | BundleExploitTechnical Analysis |
| https://github.com/AshtonKopelevich/SJ-GPS-PRO-F11-Vulnerability/security/advisories/GHSA-wph3-9w93-pxxq | [email protected] | AdvisoryTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| SJRC F11 | 2019-09-17 |
CPE
Remediation
| |
| SJRC SJ-GPS-PRO | 2019-09-17 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | CISA-ADP |
| Sep 9, 2026 | New CVE Received | [email protected] |
Volerion