Description
An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the inetd service
Published: 2026-08-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the inetd service. The impact is a potential compromise of confidentiality, allowing disclosure of confidential data to an attacker.

Affected Systems

The affected system is the SJRC F11 SJ-GPS-PRO device with firmware build 2019-09-17. No additional version information is available. The vendor is SJRC and the product is the SJ-GPS-PRO GPS device.

Risk and Exploitability

The CVSS score is 6.5 and the EPSS score is <1%, indicating a low probability of exploitation. The vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is remote exploitation through the inetd service. While no public exploit is reported, exposure of sensitive information can be critical, so the risk is considered uncertain but potentially damaging to data confidentiality.

Generated by OpenCVE AI on August 21, 2026 at 20:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for and install any firmware updates from SJRC that resolve the inetd information disclosure.
  • If a patch is unavailable, disable the inetd service or limit it to trusted hosts only.
  • Apply firewall or network segmentation rules to block remote access to the inetd port from untrusted networks.

Generated by OpenCVE AI on August 21, 2026 at 20:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure via inetd Service on SJRC F11 SJ-GPS-PRO

Fri, 21 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure via inetd Service in SJRC F11 Firmware
Weaknesses CWE-200

Wed, 19 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure via inetd Service in SJRC F11 Firmware
Weaknesses CWE-200

Tue, 18 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Description An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the inetd service
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-19T19:27:15.232Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-52480

cve-icon Vulnrichment

Updated: 2026-08-19T19:27:02.671Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T20:17:16.267

Modified: 2026-08-31T20:12:02.273

Link: CVE-2026-52480

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T20:30:07Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function