CVE-2026-52656

CRITICAL

SJCAM AllWinner Tech SJ4000-Air <= 1.4C - Remote Code Execution via Crafted FEX File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-52656. PoCs published by keowu.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-52656, targeting a buffer overflow vulnerability in SJCAM device firmware via crafted file uploads (e.g., `full_img.fex`). The PoC includes ARM-compiled binaries and scripts to trigger the vulnerability, leading to potential remote code execution by overwriting memory through malformed media files.

Description

An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute arbitrary code via a crafted FEX file

Exploits (1)

nomisec WORKING POC 8 stars
by keowu · poc
https://github.com/keowu/sjcam

This repository contains a functional exploit for CVE-2026-52656, targeting a buffer overflow vulnerability in SJCAM device firmware via crafted file uploads (e.g., `full_img.fex`). The PoC includes ARM-compiled binaries and scripts to trigger the vulnerability, leading to potential remote code execution by overwriting memory through malformed media files.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SJCAM device firmware (likely camera models with ARM-based SoCs)
No auth needed
Prerequisites: Network access to the target SJCAM device (default IP: 192.168.100.1) · Crafted media files (e.g., `full_img.fex`, `video.rgb`, `audio.pcm`) · ARM-compatible toolchain for binary compilation
mistral-large-3 · analyzed Jul 21, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0051
EPSS Percentile 40.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Published Jul 20, 2026
Tracked Since Jul 21, 2026