PT-2026-25395 · Px4+2 · Px4-Autopilot+1

Dxleryt

·

Published

2026-03-13

·

Updated

2026-03-16

·

CVE-2026-32713

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions PX4 autopilot versions prior to 1.17.0-rc2
Description A logic error exists in the PX4 Autopilot MAVLink FTP session validation. The validation uses incorrect boolean logic (&& instead of ||), allowing BurstReadFile and WriteFile operations to proceed with invalid sessions or closed file descriptors. This allows an unauthenticated attacker to put the FTP subsystem into an inconsistent state, trigger operations on invalid file descriptors, and bypass session isolation checks. The vulnerable component is the MAVLink FTP session validation logic.
Recommendations Update to version 1.17.0-rc2 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-32713
GHSA-PP2C-JR5G-6F2M

Affected Products

Px4-Autopilot
Px4 Drone Autopilot