CVE-2026-1579
CVSS 9.8 CRITICAL: the MAVLink communication protocol does not require cryptographic authentication by default.
Vulnerabilità ed exploit · Attacco IoT / OT
PX4 Autopilot — flight control software for drones and unmanned vehicles — accetta messaggi SERIAL_CONTROL MAVLink non autenticati che possono avviare una shell interattiva. La falla appare in Autopilot v1.16.0_SITL_latest_stable ed è tracciata come CVE-2026-1579. MAVLink non richiede autenticazione crittografica per impostazione predefinita, quindi le distribuzioni con MAVLink 2.0 message signing disabilitato accetteranno messaggi SERIAL_CONTROL non firmati. I settori interessati includono trasporti, difesa e altre infrastrutture critiche in cui le interfacce MAVLink sono raggiungibili.
1 fonte · 31 mar
CVSS 9.8 CRITICAL: the MAVLink communication protocol does not require cryptographic authentication by default.
CISA Advisories
PX4 Autopilot | CISA
PX4 Autopilot Summary Successful exploitation of this vulnerability could allow an attacker with access to the MAVLink interface to execute arbitrary shell commands without cryptographic authentication.
originalePart of the PlainSec briefing for 2026-04-01
Every edition of this story: Shell non autenticata via MAVLink consente l'esecuzione remota di comandi