CVE-2026-52656
CRITICALSJCAM AllWinner Tech SJ4000-Air <= 1.4C - Remote Code Execution via Crafted FEX File
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2026-52656. PoCs published by keowu.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-52656, targeting a buffer overflow vulnerability in SJCAM device firmware via crafted file uploads (e.g., `full_img.fex`). The PoC includes ARM-compiled binaries and scripts to trigger the vulnerability, leading to potential remote code execution by overwriting memory through malformed media files.
Description
An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute arbitrary code via a crafted FEX file
Exploits (1)
This repository contains a functional exploit for CVE-2026-52656, targeting a buffer overflow vulnerability in SJCAM device firmware via crafted file uploads (e.g., `full_img.fex`). The PoC includes ARM-compiled binaries and scripts to trigger the vulnerability, leading to potential remote code execution by overwriting memory through malformed media files.
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H