PT-2026-29340 · Unknown · Px4-Autopilot
Dolev Aviv
·
Published
2026-03-31
·
Updated
2026-04-15
·
CVE-2026-1579
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PX4 Autopilot (affected versions not specified)
Description
The MAVLink communication protocol, as used by PX4 Autopilot, does not require cryptographic authentication by default. Without MAVLink 2.0 message signing enabled, unauthenticated parties with access to the MAVLink interface can send messages, including the
SERIAL CONTROL message which provides interactive shell access. Enabling MAVLink 2.0 message signing in PX4 provides cryptographic authentication and rejects unsigned messages at the protocol level. The SERIAL CONTROL message allows for remote shell access.Recommendations
Enable MAVLink 2.0 message signing to provide cryptographic authentication for all MAVLink communication.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Px4-Autopilot