Impact
A flaw in the firmware of SJCAM AllWinner Tech products SJ4000‑Air V1.4C and earlier, and the corresponding Whitelabel v1.4C and earlier, permits the execution of arbitrary code when a specially crafted FEX file is processed. The vulnerability is a code injection issue (CWE‑94). If an attacker can supply a malicious FEX file—by physically loading a device or supplying data through a supported interface—the affected firmware will compile or execute that code, compromising confidentiality, integrity, and availability of the device and any connected services.
Affected Systems
The affected systems are SJCAM AllWinner Tech action cameras, specifically the SJ4000‑Air model running firmware versions up to and including V1.4C, as well as any Whitelabel variants shipped with the same firmware baseline. No additional vendor or product details are available.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. The EPSS score of less than 1% suggests that, at this time, the exploit probability is very low, though the potential impact remains severe. The flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to supply a crafted FEX file, which implies the cause is a local or removable‑media attack vector unless the device accepts such files over a network interface. The exact attack path is to have the firmware parse and execute the malicious payload contained in the FEX file.
OpenCVE Enrichment