Description
An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute arbitrary code via a crafted FEX file
Published: 2026-07-20
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the firmware of SJCAM AllWinner Tech products SJ4000‑Air V1.4C and earlier, and the corresponding Whitelabel v1.4C and earlier, permits the execution of arbitrary code when a specially crafted FEX file is processed. The vulnerability is a code injection issue (CWE‑94). If an attacker can supply a malicious FEX file—by physically loading a device or supplying data through a supported interface—the affected firmware will compile or execute that code, compromising confidentiality, integrity, and availability of the device and any connected services.

Affected Systems

The affected systems are SJCAM AllWinner Tech action cameras, specifically the SJ4000‑Air model running firmware versions up to and including V1.4C, as well as any Whitelabel variants shipped with the same firmware baseline. No additional vendor or product details are available.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity. The EPSS score of less than 1% suggests that, at this time, the exploit probability is very low, though the potential impact remains severe. The flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to supply a crafted FEX file, which implies the cause is a local or removable‑media attack vector unless the device accepts such files over a network interface. The exact attack path is to have the firmware parse and execute the malicious payload contained in the FEX file.

Generated by OpenCVE AI on July 30, 2026 at 19:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to a version newer than 1.4C once a vendor‑issued patch is available.
  • If a patch is not yet released, contact SJCAM support for a temporary fix or guidance on hardening the device.
  • Restrict or disable the device’s ability to load or execute FEX files from untrusted sources, where configuration options permit.

Generated by OpenCVE AI on July 30, 2026 at 19:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Exploitable Firmware Code Injection via Crafted FEX File in SJCAM AllWinner Tech Action Cameras

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Firmware Code Injection via Crafted FEX File in SJCAM AllWinner Tech Cameras

Sat, 25 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Firmware Code Injection via Crafted FEX File in SJCAM AllWinner Tech Cameras

Tue, 21 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute arbitrary code via a crafted FEX file
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-21T14:57:37.988Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-52656

cve-icon Vulnrichment

Updated: 2026-07-21T13:51:22.904Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T20:00:20Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')