CVE-2026-52656

SJCAM · SJ4000-Air

A critical vulnerability in SJCAM SJ4000-Air cameras allows arbitrary code execution through the processing of maliciously crafted FEX files.

Executive summary

A critical arbitrary code execution vulnerability in SJCAM SJ4000-Air cameras allows unauthenticated attackers to gain full control over the device via crafted firmware files.

Vulnerability

The device firmware contains a flaw in how it handles FEX files. An unauthenticated attacker can supply a specially crafted file to trigger code execution at the system level, leading to total compromise of the camera.

Business impact

The CVSS score of 9.8 reflects the extreme risk posed by this vulnerability, as it allows for full remote system compromise without authentication. If deployed in sensitive environments, these cameras could be weaponized to monitor physical premises or serve as an entry point for further attacks on the internal network.

Remediation

Immediate Action: Contact the vendor for specific firmware update instructions, as no public patch version is currently identified.

Proactive Monitoring: Isolate affected camera devices from critical production networks and monitor for unexpected outbound communication or unauthorized configuration changes.

Compensating Controls: Place the devices behind a restrictive firewall and disable any remote management features that are not strictly necessary for operation.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists via GitHub.

Analyst recommendation

This is a critical vulnerability that grants an attacker complete control over the affected hardware. Because there is currently no confirmed patch, users should prioritize network isolation of these devices to mitigate the risk of remote exploitation until the manufacturer provides a secure firmware update.