Impact
An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to access sensitive information through the tcp_actions() function. The flaw does not require local privileges and can be triggered over the network, enabling disclosure of potentially confidential data stored or processed by the device.
Affected Systems
The vulnerability affects devices running the SJRC F11 SJ-GPS-PRO firmware build 2019-09-17. No other product or version information is available in the current advisory.
Risk and Exploitability
The ability to obtain sensitive data remotely signifies a high risk. Attackers would likely target exposed TCP interfaces; however, the description does not explicitly state whether authentication is enforced for tcp_actions(); it is inferred that authentication may not be required, though this is not confirmed. The absence of a published exploit makes the probability uncertain, but the impact warrants immediate attention. The vulnerability is not listed in the CISA KEV, has a CVSS score of 7.5, and an EPSS score of < 1%, indicating a low likelihood of exploitation.
OpenCVE Enrichment