Impact
A flaw in the firmware of the SJRC F11 SJ-GPS-PRO (build 2019-09-17) allows a remote attacker to trigger the inetd service to spawn /app/sh_for_telnet, providing a channel to read sensitive system data. The issue enables the attacker to extract protected information, although no broad code execution or privilege escalation is described in the advisory. This aligns with a classic information exposure vulnerability potentially coupled with command execution through the inetd environment.
Affected Systems
The affected product is the SJRC F11 SJ-GPS-PRO GPS device running the 2019‑09‑17 firmware build. No vendor or product name is listed in the CNA data, and no version range beyond this build is provided; security teams should therefore verify whether their devices are running this specific firmware revision or later revisions that may mitigate the issue.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating that documented exploitation is currently unknown. Nonetheless, the remote trigger via inetd suggests that an attacker could access the vulnerable service from outside the immediate network. Because the flaw is remotely exploitable, the risk depends largely on network exposure; with open telnet access the threat is higher, whereas isolated or firewalled devices mitigate immediate danger.
OpenCVE Enrichment