Impact
A flaw in the firmware of the SJRC F11 SJ-GPS-PRO (build 2019-09-17) allows a remote attacker to trigger the inetd service to spawn /app/sh_for_telnet, providing a channel the attacker to extract protected information, although no broad code execution or privilege escalation is described in the advisory. This aligns with a classic information exposure vulnerability potentially coupled with command execution through the inetd environment.
Affected Systems
The affected product is the SJRC F11 SJ-GPS-PRO GPS device running the 2019‑09‑17 firmware build. No vendor or product name is listed in the CNA data, and no version range beyond this build is provided; security teams should therefore verify whether their devices are running this specific firmware revision or later revisions that may mitigate the issue.
Risk and Exploitability
The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV. The CVSS score of 7.5 reflects moderate severity. Nonetheless, the remote trigger via inetd suggests that an attacker could access the vulnerable service from outside the immediate network. Because the flaw is remotely exploitable, the risk depends largely on network exposure; with open telnet access the threat is higher, whereas isolated or firewalled devices mitigate immediate danger.
OpenCVE Enrichment