CVE-2026-52482

SJRC · F11 SJ-GPS-PRO

A security flaw in the SJRC F11 SJ-GPS-PRO drone firmware allows unauthenticated remote attackers to access sensitive information via a telnet service.

Executive summary

A critical information disclosure vulnerability in the SJRC F11 SJ-GPS-PRO firmware allows unauthenticated remote attackers to gain unauthorized access to sensitive system data.

Vulnerability

The vulnerability exists due to an improperly configured inetd service that spawns a shell for telnet, allowing any unauthenticated remote attacker to access the device.

Business impact

The ability for an unauthenticated attacker to remotely access sensitive information presents a significant risk to operational security and user privacy. Given the CVSS score of 7.5, this high severity flaw could lead to the exposure of proprietary flight logs or device configurations, potentially resulting in device compromise or unauthorized surveillance.

Remediation

Immediate Action: Disable telnet access on the affected device if the configuration allows, and restrict network exposure by isolating the device from the public internet.

Proactive Monitoring: Monitor network traffic for unauthorized telnet connection attempts directed at the drone or its associated command and control infrastructure.

Compensating Controls: Deploy network-level access controls or a firewall to block inbound connections to the device on the telnet port (typically TCP 23).

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as documented in the GitHub security advisory referenced by the CVE record.

Analyst recommendation

Users of the SJRC F11 SJ-GPS-PRO should treat this vulnerability with high priority, as it permits remote, unauthenticated access to system components. Because a formal firmware patch is currently unavailable, administrators must implement strict network segmentation to prevent external exposure of the device until a vendor-supplied update is verified and applied.

History

CVE Brief tracked this CVE 5 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.5 (3.1)
  4. Analyst report written

Sources