PT-2026-25395 · Px4+2 · Px4-Autopilot+1
Dxleryt
·
Published
2026-03-13
·
Updated
2026-03-16
·
CVE-2026-32713
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
PX4 autopilot versions prior to 1.17.0-rc2
Description
A logic error exists in the PX4 Autopilot MAVLink FTP session validation. The validation uses incorrect boolean logic (&& instead of ||), allowing
BurstReadFile and WriteFile operations to proceed with invalid sessions or closed file descriptors. This allows an unauthenticated attacker to put the FTP subsystem into an inconsistent state, trigger operations on invalid file descriptors, and bypass session isolation checks. The vulnerable component is the MAVLink FTP session validation logic.Recommendations
Update to version 1.17.0-rc2 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Px4-Autopilot
Px4 Drone Autopilot