CVE-2026-52482
moderateTelnet-Backed Information Disclosure in SJRC F11 SJ-GPS-PRO Drone Firmware
The SJRC F11 SJ-GPS-PRO drone running firmware build 2019-09-17 is vulnerable to unauthenticated information disclosure (CWE-200) because the device's inetd daemon spawns a shell-for-telnet service (/app/sh_for_telnet). An attacker who can reach the drone over its network interface, such as its WiFi link, can connect to this telnet-backed service and read sensitive data from the device with no credentials or user interaction. The flaw carries a CVSS 3.1 base score of 7.5 (high confidentiality impact; no integrity or availability impact), so an attacker gains access to confidential drone data but cannot directly modify or crash the device. Owners of this budget consumer drone are the affected population. Exploitation is currently unlikely: EPSS is only 0.2% (11th percentile), no public proof of concept exists, and the CVE is not in CISA's KEV catalog.
What to do: Check with SJRC for any firmware update newer than the 2019-09-17 build and apply it if one exists. Since no patch is confirmed, treat the drone's WiFi link as untrusted: avoid flying or pairing the drone in public or crowded RF areas where an attacker could be in range, and power the drone off when not in use. Review the companion app and controller for stored sensitive data (saved locations, credentials) and remove anything not needed.
| SJRC F11 SJ-GPS-PRO (drone) | firmware build 2019-09-17 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the inetd service spawns /app/sh_for_telnet
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.