Executive brief
SJCAM SJ4000-Air action cameras and similar generic models are vulnerable to a security flaw that allows for the execution of unauthorized code. By providing a specially crafted configuration file (FEX file), an attacker could gain full control over the device's operating system. This could lead to the theft of recorded media, unauthorized monitoring, or permanent disabling of the camera.
Technical details
A vulnerability exists in the firmware update or configuration handling of SJCAM SJ4000-Air (V1.4C and prior) and related Whitelabel AllWinner Tech-based products. The devices fail to properly validate FEX files, which are used for hardware configuration and initialization on AllWinner platforms. An attacker can leverage a crafted FEX file to achieve arbitrary code execution. While the attack vector typically requires local access to the device's storage (e.g., via SD card) or a physical connection, it allows for complete system compromise. No official patch is currently noted in the advisory, though third-party research into open-source firmware alternatives has been documented.
Affected products
- SJCAM SJ4000-Air V1.4C and earlier
- Whitelabel Whitelabel AllWinner Tech Action Camera V1.4C and earlier
Timeline
- 2026-07-20: advisory: CVE published by NVD/MITRE