Executive brief
The SJRC F11 SJ-GPS-PRO consumer drone's telnet service (port 23) spawns an unauthenticated root shell, allowing anyone connected to the drone's WiFi network to gain complete administrative access. An attacker can remotely execute arbitrary commands with root privileges, read/modify sensitive flight data and configurations, or disable the device entirely.
Technical details
The vulnerability is a missing authentication mechanism in the inetd service, which spawns /app/sh_for_telnet directly as root on TCP port 23. This binary is a wrapper that invokes system("/bin/sh -l") without any credential validation. The attack requires only network adjacency—connection to the drone's open WiFi access point—with no further authentication or user interaction needed. An unauthenticated attacker can establish a telnet connection and immediately obtain a root shell, enabling remote code execution, data theft, and device manipulation. No patch is known to exist as of the disclosure date (August 2026).
Affected products
- SJRC F11 SJ-GPS-PRO firmware build 2019-09-17
Timeline
- 2026-08-15: disclosed: Public disclosure via GitHub
- 2026-08-16: advisory: GitHub security advisory GHSA-wph3-9w93-pxxq published
- 2026-05-17: other: Vendor SJRC notified; no response received